If you'd found the same class of vulnerabilities in Intel SGX or the iPhone SEP, you'd have a contender for the top vulnerability discovery of the year; an almost-lock on the Pwnie.
I simply can't understand the people who are downplaying this other than by assuming that people love AMD so much that they don't want these to be severe vulnerabilities.
Do I think this will move the stock? No. I don't think an SGX break would hurt Intel much either.
Yep, you should consider them burned. Also make sure you stock up on tinfoil too as you’ll need to make sure the fresh replacement keys don’t get mind read from a distance.
</sarcasm>
In all seriousness, what part of this situation would lead you to think what you’re saying? There’s been good coverage of what it’d take to exploit these vulnerabilities, so I’m not sure what lead you to this line of reasoning.
* if yes, what are the ways that one could get root on that machine? Is it better or worse on the MBP?
* if not, are the keys stored in a place which is related to the secure processor?
And also: is there a reason why somebody could 1) know that you have keys on that machine 2) be interested in those keys 3) have the resources to conduct the attack?
In a nutshell, analyze your attack surface and model your threats.
When I say "pedestrian" vulnerabilities, what I mean is that most users should wait for the patch to come out and apply it, but otherwise not panic. It's definitely not Heartbleed-class "you need to have patched yesterday and, if you haven't, you're already compromised."
These reported errors, while quite severe for what i've been able to make out of the less-than-good paper, do not grant a primary mode of attack and do not provide a way of getting privileges. Just a way of keeping it forever and ever and ever and ever ...
Should be fixed and done properly, just get the fucking CVEs already and publish it ... It is highly likely that it's in some way applicable to other secure elements on other cpu's as well so a proper response is needed.
The basis of this is mostly you just saying it emphatically, as far as I can tell. Most real-world exploits rely on a combination of vulnerabilities. What's a sensible ranking of 'remote' over 'persistent'?
just get the fucking CVEs already
What does this really have to do with anything? It's hard to imagine anyone dealing with a real deployed system saying 'Well, since there is no CVE, this does not affect us at all".
That being said with their shady behaviour CTS-labs have managed the tour de force of overshadowing these vulnerabilities with their botched hit piece "reveal". Paradoxically AMD might end up receiving less backlash than they deserve for their shoddy work because the researchers tried to pull a quick scam out of it. Great job CTS-labs.
I mean, it's cool from a security research perspective, the PSP isn't just some random keyboard/HDD, but the severity seems overstated.
I'm saying that the inverse argument, that the vulnerabilities are "pedestrian" and not worth making noise about, is at least equally false.
Unfortunately, the day of the announcement, several people trafficked in opinions based on CTS-Labs white paper --- which any skilled reader knew immediately, just from the format, wasn't a technical explanation --- that these vulnerabilities were non-issues. If I see people repeating that notion, I'm going to point out: the equivalent vulnerability in the iPhone platform would be front-page news.
> "All exploits require the ability to run an executable as admin"
> "There is no immediate risk of exploitation of these vulnerabilities for most users."
> "These types of vulnerabilities should not surprise any security researchers; similar flaws have been found in other embedded systems that have attempted to implement security features."
Sounds pretty pedestrian.
Parse error. Did you mean "than systems that don't"?