Google's response to Reptar CPU vulnerability
bughunters.google.com
bughunters.google.com
For VMs running in GCP, they do migrate VMs across machines from time to time, and you could handwave a process where they take a machkne, update the hypervisor image with new microcode, migrate all VMs off the machine, then make it available to receive VM migrations. Migrating a VM is disruptive, although the disruption is brief.
Not only that. There were microcode updates which disabled CPU features (most notably TSX). During process startup such features might have been detected as available and decided to use optimized subroutines. Disabling features while the process is still running might either severely degrade performance or outright crash it.
[1] https://www.gnu.org/software/libc/manual/html_node/Elision-T...
Also the amount of stuff he finds alone makes you think about how much stuff gov agencies find.. they get a lot of smart people as well.
Occam's razor: They do it like everyone else.
imagine a google peace maker. lol
In microcode update case it's not much help for developing an exploit when it's encrypted.
I don't quite understand how this issue can be a DoS vector, and 'maybe' lead to info disclosure...
If the only issue is that a machine check exception is thrown when it shouldn't be, then I don't see how that leads to info disclosure...
In other words: just marketing.
It is a crash that requires a reboot of the computer.
Therefore a rogue VM can take down the hypervisor and all the other VMs hosted on the same server.
The bug is that according to the x86-64 ISA specification that sequence of instruction prefixes should have caused an illegal instruction exception, but it does not cause any exception. Instead of that, it desynchronizes the microcode execution and the CPU executes other microinstructions than it should, leading into a crash.
Typically these are are hard to pull off, I remember a case a number of years ago where the proof of concept private key exfiltration came months or maybe even a year after the vulnerability was shown, and even then I believe the process took minutes or perhaps hours to run. This stuff isn't magic, it's really hard, but that doesn't mean it's not possible.
> In general, if the cores are SMT (Symmetric Multithreading) siblings, then you may observe random branches, and, if they're SMP (Symmetric Multiprocessing) siblings from the same package, then you may observe machine checks.
[...]
> However, we simply don't know if we can control the corruption precisely enough to achieve privilege escalation. I suspect that it is possible, but we don't have any way to debug μop execution!
The exploit they published crashes the machine, but it may be possible to write one that does other things, they just don't know how.
Actually useful blog post: https://bughunters.google.com/blog/5997221712101376/the-rept...
Tavis.
Unless they run their datacenter at redline all the time, there should be plenty of spare resources to shift load and bring a machine down for maintenance. Right?
I really don't understand how the risk of crashing programs or introducing undetectable errors outweighs the effort of rolling the update out gradually. surely they have an automated system that can shut down any number of machines without disrupting the network?
Then again I have no idea what a datacenter on Google's scale even looks like. Maybe there's some crucial reason they can't shut down any machines at all ever. Smells bad to me though.
I wonder to what extent the security industry is self-reinforcing and how many of these vulnerabilities would be discovered by 'the bad guys' taking into account that none of them have these kind of resources. But now the rest of the world has to deal with the fall-out of the disclosure that Google got a head start on and can relatively easily deploy across their cloud. It feels a bit like the hero model to me: only we can keep you safe from the problems that we create.
> From there, Google partnered and collaborated with Intel to securely share the vulnerability mitigation information with other large industry players to ensure they too could respond and protect all users globally (not only Google users).
So while the blog post of course is marketing, Google does not gain any direct competitive advantage from the vulnerability, all the large clouds are more or less on the same starting line.
Really seems like there’s no winning for Google in the public narrative!
State actors definitely have these resources. USA, China, Russia at a minimum. I definitely feel the angst against the effort it takes to protect against bad actors. For example the adoption of https/ssl had a lot of worry about how expensive it was to encrypt server traffic. There were people arguing that it just wasn't worth it because the risk felt low, but it turns out the compromising was happening in practice. The ability to not have to guard against bad actors would make implementing technology a radically simpler endeavor, we just simply don't live in that world.
Do they? Amazon and Google level knowledge, both from live systems with data like all of Google and Amazon, but also the developers and analysts to look through data from it and to comb through source code? I very much doubt Russia has this at least, but it is a widespread American point of view that Russia has, well, basically everything one day and nothing at all the next (IE. Ukraine war). I doubt anyone -except maybe the US- has this.
Have the resources to develop zero days? Of course they do. Like, even Iran, North Korea, Uzbekistan, Vietnam, etc have the resources required to either make their own zero days, pay someone unscrupulous for it or acquire them some other way. It only costs a few million.
Works wonders for Apple. ("look, we fixed the bug discovered by Citizenlab").
Security, unfortunately, has become theater. There are some things fixed when and if they are disvovered but, in general, the main issues were not adressed (fine grained permissions, web browser as remote code executor, etc).
if the cure for cancer is offerred as a subscription model, that requires an active Google account, well...
Also, how many vulnerabilities relevant to public clouds does Google detect in one year, and does that outweigh the lack of support and care you can expect from Google?
The article says they didn't wait, but got informed.
I grew up in a world where everything was hackable. Chrome (and Firefox, but it really doesn't matter anymore) become less and less modifiable and adaptable. In theory and practice.
I think the main reason there is no viable alternative browser is that it has become far too complicated and far to much effort to write and maintain one. But - and here comes the point - even if we could muster the resources to pull one off, we'd never gain enough trust that it is as secure as Chrome to make it even remotely popular.
As long as things are as they are, it is a game we're never gonna win.
> What prevents literally anybody from continuing to support Chromium? Has Microsoft ran out of competent engineers?
Remember that Microsoft failed at its promise of if we don't match Chrome bug for bug, that is a defect in Edge. They failed and they gave up trying. My personal conspiracy theory is that it costs well over a billion dollars a year, not including marketing dollars or bribery dollars, just to keep Chrome running.
I don't think Google will pull the rug on Chromium but then again all bets are off if Google has new overlords or if Google isn't making that USD 200B+ revenue year over year. Things feel permanent probably right before giving up the ghost. I think if Microsoft felt like it could avoid using Chromium with its own stuff, it would have never touched Chromium.
tl;Dr I doubt Microsoft will put in the money or energy it takes to maintain Chromium.
It's actually a little interesting, why did they choose Chromium in the first place over firefox, when Microsoft and Google are more directly competitors?
Considering how many companies depend on working with Chromium there is financial backing for funding development if Google were to go away. It is the browser in the most favorable position for if this were to happen.
Web browsers on the other hand have become so complex that is no longer possible without an enourmous amout of resources so you really are dependent on big G to keep feeding you updates. This complexity is at least part due to the ever increasing number of standards and expanding scope that Google themselves are pushing for.
You ask what if Google one day yanks the rug out, and the answer is, plenty of large companies will fork it.
What are you talking about? That was the prime of Firefox and browser modification
My point is that these forks are futile because it takes only one major vulnerability - found by Project Zero and publicized with Google's might - to blow you out of business.
The vast majority of people do not care about security, privacy, etc. at all.
Chrome achieved dominion simply because it's better to use than anything else, it also doesn't help that Firefox also Mozilla'd itself into irrelevance.
Grandiose "expert" posturing, focusing exclusively on corporate bullshit hierarchy while being scarce on meaningful details. So they chose to hotload the microcode patch instead of rebooting, that's the only actual piece of information.
https://www.intel.com/content/www/us/en/security-center/advi...
It's interesting that Intel more or less hints at having been aware of this before Google reported it. Also: a lot of fear mongering about information disclosure but there is afaik no proof of concept for that (though eventually a way might be found to do that it isn't the case right now).
It's a hardware bug and it's been reported, that doesn't really seem like enough time to start holding people's ears to the fire.
Value to Google came in the form of attracting top talent because it indicated it was more than a version of oracle/ibm focused on nothing but money making.
It also came in the form of feedback on how to improve software security in general. Google was also able to tap the team resources to look into the security of a new proposal.
8 years ago if the notion of “we’ll sit on vulnerabilities, patch them in our products, and use that as advertising for the products” came up, it would be laughed out of the room.
People joined project zero to do cutting edge research and improve the world, not to line Google’s pockets through early disclosure access.
The reputation damage to that team for being tangled in GCP shilling is subtle but immense. Pure security researchers will be driven away by this kind of thing and just stick with academia or other research institutions.
Demonstrated by said researchers publishing under the Google brand.