• Uh Oh - NEW Data Leak Found in Intel Processors

    From c186282@c186282@nnada.net to talk.politics.misc,alt.security,comp.os.linux.misc,alt.politics on Wednesday, May 21, 2025 20:20:09
    From Newsgroup: alt.security

    https://scitechdaily.com/intels-memory-leak-nightmare-5000-bytes-per-second-in-the-hands-of-hackers/

    Computer scientists at ETH Zurich have uncovered a serious
    flaw in Intel processors that could let attackers steal
    sensitive information by exploiting how modern chips predict
    upcoming actions. Using specially designed sequences of
    instructions, hackers can bypass security boundaries and
    gradually read the entire memory of a shared processor.
    This vulnerability affects a wide range of Intel chips
    used in personal computers, laptops, and cloud servers.

    Researchers identified a new class of vulnerabilities in
    Intel CPUs linked to speculative execution — a technique
    that helps processors work faster by predicting the
    next steps.

    The flaw allows attackers to break down barriers between
    users sharing the same processor, potentially accessing
    private data stored in memory.

    By repeating the attack at high speed, hackers can extract
    memory content byte by byte until the full contents are
    revealed.

    . . .

    Sounds too complex for broad use on 'home' systems
    but becomes more of an issue if you're "important",
    big biz, bank, defense. Orgs that save money by using
    very 'thin' clients, where most of the work is done
    by a single kick-ass box, may risk rather broad
    exposure to this new hacking approach. Hmmm ...
    Office365-online kinda does this ....

    Alas, speculative execution is one of the things
    that put a lot more pop into modern CPUs. Turn
    if off and you step back YEARS performance-wise.

    Similar issues may exist for other CPUs, but Intel
    gets the most press.

    Vlad and Xi's bad boyz .. they have State resources,
    time and energy. They will pound CPUs and systems
    relentlessly looking for the slightest 'in'. Good
    chance they knew about this issue well before any
    'professionals' did.


    --- Synchronet 3.21e-Win32 NewsLink 1.2
  • From Grimble Crumble@grimblecrumble870@gmail.com to alt.politics,talk.politics.misc,alt.security,comp.os.linux.misc on Thursday, May 22, 2025 10:18:31
    From Newsgroup: alt.security

    c186282 <c186282@nnada.net> wrote:
    https://scitechdaily.com/intels-memory-leak-nightmare-5000-bytes-per-second-in-the-hands-of-hackers/

    Computer scientists at ETH Zurich have uncovered a serious
    flaw in Intel processors that could let attackers steal
    sensitive information by exploiting how modern chips predict
    upcoming actions. Using specially designed sequences of
    instructions, hackers can bypass security boundaries and
    gradually read the entire memory of a shared processor.
    This vulnerability affects a wide range of Intel chips
    used in personal computers, laptops, and cloud servers.

    Researchers identified a new class of vulnerabilities in
    Intel CPUs linked to speculative execution — a technique
    that helps processors work faster by predicting the
    next steps.

    The flaw allows attackers to break down barriers between
    users sharing the same processor, potentially accessing
    private data stored in memory.

    By repeating the attack at high speed, hackers can extract
    memory content byte by byte until the full contents are
    revealed.

    . . .

    Sounds too complex for broad use on 'home' systems
    but becomes more of an issue if you're "important",
    big biz, bank, defense. Orgs that save money by using
    very 'thin' clients, where most of the work is done
    by a single kick-ass box, may risk rather broad
    exposure to this new hacking approach. Hmmm ...
    Office365-online kinda does this ....

    Alas, speculative execution is one of the things
    that put a lot more pop into modern CPUs. Turn
    if off and you step back YEARS performance-wise.

    Similar issues may exist for other CPUs, but Intel
    gets the most press.

    Vlad and Xi's bad boyz .. they have State resources,
    time and energy. They will pound CPUs and systems
    relentlessly looking for the slightest 'in'. Good
    chance they knew about this issue well before any
    'professionals' did.




    The NSA has attempted to build backdoors into computers and cryptography
    for awhile now. While I have no proof, and frankly don't suspect, that
    they're responsible for this one specifically, privacy and the government
    are nearly mutually exclusive right now in digital communications and technology. The fundemental issue (besides the obvious privacy violation)
    is that their backdoors can be exploited by anyone as well. The whole idea
    is ridiculous; yet, they haven't given up. Call me crazy.

    https://www.atlasobscura.com/articles/a-brief-history-of-the-nsa-attempting-to-insert-backdoors-into-encrypted-data

    https://www.tweaktown.com/news/32067/amd-and-intel-in-bed-with-nsa-are-backdoors-built-into-processors-/index.html
    --
    Ouvre le chien
    --- Synchronet 3.21e-Win32 NewsLink 1.2
  • From The Natural Philosopher@tnp@invalid.invalid to alt.politics,talk.politics.misc,alt.security,comp.os.linux.misc on Thursday, May 22, 2025 20:08:03
    From Newsgroup: alt.security

    On 22/05/2025 16:18, Grimble Crumble wrote:
    The NSA has attempted to build backdoors into computers and cryptography
    for awhile now. While I have no proof, and frankly don't suspect, that they're responsible for this one specifically, privacy and the government
    are nearly mutually exclusive right now in digital communications and technology.
    No, they are not responsible for this one. Its the way computers work
    that is the problem and he way they have been optimised to work faster.
    --
    "The most difficult subjects can be explained to the most slow witted
    man if he has not formed any idea of them already; but the simplest
    thing cannot be made clear to the most intelligent man if he is firmly persuaded that he knows already, without a shadow of doubt, what is laid before him."

    - Leo Tolstoy


    --- Synchronet 3.21e-Win32 NewsLink 1.2
  • From c186282@c186282@nnada.net to alt.politics,talk.politics.misc,alt.security,comp.os.linux.misc on Friday, May 23, 2025 02:07:42
    From Newsgroup: alt.security

    On 5/22/25 3:08 PM, The Natural Philosopher wrote:
    On 22/05/2025 16:18, Grimble Crumble wrote:
    The NSA has attempted to build backdoors into computers and cryptography
    for awhile now. While I have no proof, and frankly don't suspect, that
    they're responsible for this one specifically, privacy and the government
    are nearly mutually exclusive right now in digital communications and
    technology.
    No, they are not responsible for this one. Its the way computers work
    that is the problem and he way they have been optimised to work faster.

    Fully true.

    "Speculative"/"predictive" execution is a major
    reason modern CPUs are so fast. It's a HARDWARE
    decision - but SOMEBODY has found ways to
    exploit it, at least in Intel processors.

    We're talking little hacks, probably with
    State-level backing. They can try EVERYTHING,
    just POUND at every possible flaw.

    THEY will find it well before the rest of us.
    NOT good.
    --- Synchronet 3.21e-Win32 NewsLink 1.2