6 ms·
Flaw in AMD chips allows virtually unfixable infections
- wordofx 2y agoSince when is wired.com paywalled?
- choppaface 2y agoFYI HN mods consider paywalled to be off-topic for HN and thus liable for moderating action. Even though WSJ and others are paywalled and HN readers don’t care.
- lostmsu 2y agoRequires root.
- signa11 2y agofta we have this: ''' Nissim and Okupski note that exploiting the bug would require hackers to already have obtained relatively deep access to an AMD-based PC or server, but that the Sinkclose flaw would then allow them to plant their malicious code far deeper still. ''' and then this: ''' To take advantage of the vulnerability, a hacker has to already possess access to a computer's kernel, the core of its operating system. ''' so it is click-bait ?
- ec109685 2y agoIt enables persistence (the part about it being unfixable seems click baity though): “any machine with one of the vulnerable AMD chips, the IOActive researchers warn that an attacker could infect the computer with malware known as a “bootkit” that evades antivirus tools and is potentially invisible to the operating system, while offering a hacker full access to tamper with the machine and surveil its activity. For systems with certain faulty configurations in how a computer maker implemented AMD's security feature known as Platform Secure Boot—which the researchers warn encompasses the large majority of the systems they tested—a malware infection installed via Sinkclose could be harder yet to detect or remediate, they say, surviving even a reinstallation of the operating system.
- sebazzz 2y agoSince the code would then run at ring -2, would it be possible to decrypt the microcode of the CPU, or load custom microcode?