Meltdown and Spectre: Bugs in modern computers leak passwords and sensitive data
meltdownattack.com
meltdownattack.com
This is a nightmare for the cloud, but IMHO for personal computing, it only furthers the notion that you should trust every bit of code running on your system, and my long-standing view that protection features like paging, rings, and access bits should really be considered more of barriers to prevent accidents than any real isolation. Timing-based sidechannels are notoriously difficult to excise completely.
> In particular, we have verified Spectre on Intel, AMD, and ARM processors.
Interesting. So there are two different vulnerabilities. Spectre has been verified to affect Intel and AMD whereas Meltdown may affect both.
Edit: based on this statement,[1] AMD states they are not affected at all. This seems to be contrary to what the researchers have found?
>The Project Zero researchers discovered three methods (variants) of attack, which are effective under different conditions. All three attack variants can allow a process with normal user privileges to perform unauthorized reads of memory data, which may contain sensitive information such as passwords, cryptographic key material, etc.
> There is no single fix for all three attack variants; each requires protection independently. Many vendors have patches available for one or more of these attacks.
That would suggest the possibility of a third unnamed attack variant.
[0] https://security.googleblog.com/2018/01/todays-cpu-vulnerabi...
When AMD says they are "not susceptible to all three variants", that's a NAND, not a NOR.
Meltdown is more severe with read privilege escalation (javascript in browser could read kernel memory!), which has a kernel patch (KPTI) that can slow down many workloads by 30%.
Spectre also allows a user process to read memory of other processes/containers and potentially kernel, which was shown to work on Intel and ARM64 because their predictable branch prediction impl (Tomasulo). Newer AMD (Ryzen and Epyc) employs a hardware neural network for branch prediction, which is much less predictable but still theoretically possible to exploit. This is probably not the first time that the opacity of a neural network helped security :)
From https://aws.amazon.com/de/security/security-bulletins/AWS-20...:
"While the updates AWS performs protect underlying infrastructure, in order to be fully protected against these issues, customers must also patch their instance operating systems."
Prior to this quote, Amazon said that virtually all of the underlying instances have been patched.
What's the risk between now and when all of my EC2 instances are restarted with updated AMIs? Is it the 'full' risk, or is the attack less feasible, given the patched underlying OS'. Thanks.
However, from what I'm understanding, this makes Heartbleed look like a papercut.
… and nowadays almost everyone permits remote sites to execute code in their browsers. I don't know if JavaScript can be used to implement Meltdown though.
This research has implications for products and services that execute externally supplied code, including Chrome and other browsers with support for JavaScript and WebAssembly.
Edit: Wait, sorry, I misread. Read is all you really need, write would just be a cherry. If you can read the memory of the host kernel, then you can gain access to any other VMs on the system. This one is bottom-up, you need access to one system and in theory you can gain access to thousands.
https://freedom-to-tinker.com/2005/09/09/acoustic-snooping-t...
Has anyone applied similar methods to pen on paper?