Researchers discover potentially catastrophic exploit present in AMD chips
engadget.com
engadget.com
(PS if you're worried about the illegibility of your computer's storage devices and your resulting inability to completely wipe it and reinstall, then that sounds like a problem with your motherboard!)
> Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is enabled, potentially leading to arbitrary code execution.
Whether you think someone is motivated enough to find a kernel exploit that can trigger this issue and then go through the trouble of exploiting not just the kernel but this very specific CPU issue that exists on certain processors is up to you. Is it likely? I'd say no. Is it possible? Yes. Should you care? Yes. Should you lose sleep? Probably not.
If you're a person who needs to be careful about this sort of stuff (e.g., you're Edward Snowden or run Iran's nuclear program), you hopefully are already paying attention. If you are a mere muggle like the rest of us, the risk is probably not high enough for you to get upset.
https://www.techdirt.com/2015/08/13/lenovo-busted-stealthily...
https://www.dell.com/support/kbdoc/en-us/000130396/what-is-a...
https://i.dell.com/sites/content/business/solutions/brochure...
this all comes from the work AMD did on the xbox hypervisor, and obviously a console needs to be physically present (sitting in the attacker's living room) and survive a complete compromise of a guest partition (again, potentially including the OS/"bare-metal guest").
https://www.youtube.com/watch?v=U7VwtOrwceo
why would ring0 ever be intended to grant you access to ring -1 or -2? why even have rings -1 or -2 in that situation?
secure encrypted virtualization is supposed to be "homomorphic encryption, but in a system we can actually implement/that actually performs decently". obviously it would be reassuring to know that hetzner can't look at your data that you put into the hardware they own, right?
how do you accomplish that if not creating a root-of-trust that's not controlled by the owner of the machine? I don't trust Hetzner to not see my data, but I might be willing to trust AMD. Let AMD hold the key to my VM memory partition, and the hypervisor exists in a different VM memory partition, and its keys don't work in my partition.
Things which break that security model are obviously of huge concern and it feels borderline intentionally-misleading to phrase it as "why would you be concerned about that". The answer is because it's a foundational break in the security model of SEV and the PSP.
You immediately fall into trusting-trust problems around working in an inherently compromised environment where an attacker can manipulate you in arbitrary ways. You think reading a file twice produces the same results? You think adding two numbers or doing an if-statement returns the proper result? Not if the hardware is malicious.
Beyond the broader “should this exist”, once it is a given that it exists, it’s an incredibly powerful weapon and it certainly shouldn’t be left unsecured. This is the thing that can see the true state of memory, hold all the keys, and even just arbitrarily rewrite memory state or processor state. This is god on this system.
The fact that people see that and say “well you’d have to type sudo to permanently own the machine!” as some kind of excuse or downplaying is nuts and wouldn’t be tolerated from any other brand. But AMD always gets extra benefit-of-the-doubt and kid-glove treatment.
When intel gets compromised nobody does the “ok but should we really have a hypervisor ring anyway???” shit. The amount of special pleading people do on behalf of AMD is insane.
And people would never tolerate intel leaving a bunch of hardware exploits unpatched like some of AMD’s exploits have been.
yes, that’s the weird sickly affection for AMD, and the weird sickly philosophical defense of a high-severity CVE on pseudointellectual principles.
people would really rather we rethink the whole of secure-boot rather than admit AMD has a serious bug they won’t fix, lol
I'm also happy that you can get a cheap converter to plug your Ryobi batteries into your DeWalt drill, breaking their anti-consumer "features". Likewise with third party printer ink. All good stuff.
So that’s pretty bad. Kernel exploits aren’t that hard to find and it looks like this bug gives a path from kernel exploit to exploit persistence, with the only way to get rid of the persisted exploit is to throw away the CPU.
If I’m understand it right then, like, yikes!
Similar mechanisms were demoed in the ryzenfall exploit series like 5+ years ago.
using SMM calls to jump to arbitrary code execution/control of the PSP is a big deal, that’s what happened before and probably what’s happened here.
It looks bad but this phrase looks even worse for AMD: "No fix planned"[1].
Finally internalizing themselves as the winner and starting to pull an Intel?
[1] - https://www.amd.com/en/resources/product-security/bulletin/a...
I just built a gaming PC with a Ryzen 3600. It is more than sufficient to run modern games with demanding graphics and performance. I now need to learn about this exploit. Yes, if someone gets the level of access required to exploit it I was pwned anyway, but now if I get pwned I need to open up my computer and throw away a perfectly powerful CPU, then put it back together with a new one.
That's pretty damn frustrating. It will definitely push me away from AMD when I am making future hardware decision.
EDIT: As pointed out by sqeaky and others, there shouldn't be a method for persistence that lives on the processor, instead it would likely be on the motherboard, or in the bootloader on a storage device.
I don't think there's any indication that the exploit allows the CPU itself to be persistently infected.
> As a matter of fact, the researchers say that the code would likely survive a complete reinstallation of the operating system. The best option for infected computers would be a one-way ticket to the trash heap.
From the Wired article (https://www.wired.com/story/amd-chip-sinkclose-flaw/):
> In fact, for any machine with one of the vulnerable AMD chips, the IOActive researchers warn that an attacker could infect the computer with malware known as a “bootkit” that evades antivirus tools and is potentially invisible to the operating system, while offering a hacker full access to tamper with the machine and surveil its activity. For systems with certain faulty configurations in how a computer maker implemented AMD's security feature known as Platform Secure Boot—which the researchers warn encompasses the large majority of the systems they tested—a malware infection installed via Sinkclose could be harder yet to detect or remediate, they say, surviving even a reinstallation of the operating system.
> Only opening a computer's case, physically connecting directly to a certain portion of its memory chips with a hardware-based programming tool known as SPI Flash programmer and meticulously scouring the memory would allow the malware to be removed, Okupski says. Nissim sums up that worst-case scenario in more practical terms: “You basically have to throw your computer away.”
Do you have differing information?
Consider that even things like CPU microcode don't get stored on the CPU, it's simply doesn't have persistent storage. CPU microcode is often applied early during OS boots and loaded into memory or CPU cache.
What you have quoted indicates something similar, perhaps the main board or other device with storage of some kind is being written to or perhaps an attacker could write a payload that lived entirely in the bootloader on the main storage.
If you can't do that, then this feels significantly less problematic.
> For systems with certain faulty configurations in how a computer maker implemented AMD's security feature known as Platform Secure Boot
Seems like this actually requires two vulnerabilities, then?
Intel CPUs have been self-destructing, so you need to throw away CPUs even if they aren't pwned. They have also had far more security vulnerabilities than AMD, some of them cannot be patched, and operating systems had to work around them. Heck, the Sinkclose name came from 'Sinkhole', which was an Intel vulnerability.
No manufacturer is perfect.
It's from the Jul 2019. Not very old. CPUs from the early 2010s, with enough ram, are still perfectly usable for light browsing and text editing tasks.
Chips from the early 2010s are very old and inefficient - it’s just that you listed tasks that demand nothing, and if battery power is not required it will certainly do the trick.
Being very old and being usable are very things, as any senior person or tech collector will tell you.
No, I will contest <5 years old CPUs being called "old". This perspective is warped by the marketing teams of computer hardware companies. There are many 3000 series processors which are perfectly powerful enough for powerful modern software.
There is nothing wrong with using or intentionally buying old things that work. But being “powerful enough to run modern software” doesn’t mean more than “is AMD64 and support a minimum of 8GB of RAM”. I also have a 3rd gen intel i7’s laptop that is “powerful enough to run modern software”, but it’s still very old and incredibly power hungry for the little work it does. I also have a 14 year old car that performs its functions as well as when it was new - much to my dismay - but it’s still objectively old.
> But being “powerful enough to run modern software” doesn’t mean more than “is AMD64 and support a minimum of 8GB of RAM”. I also have a 3rd gen intel i7’s laptop that is “powerful enough to run modern software”, but it’s still very old and incredibly power hungry for the little work it does.
If the hardware can run just fine, what makes it old? Why call it old? Increased power efficiency? That is a good thing to strive for, but from a carbon emissions perspective, most computers cost much more carbon to manufacture than to operate across their lifespan.
> I also have a 14 year old car that performs its functions as well as when it was new - much to my dismay - but it’s still objectively old.
It isn't "objectively" old. "Old" does not have an objective definition. I also have a 14 year old car, that I do not consider to be old. I don't consider it to be old because it functions well, matches the aesthetic style of the majority of cars on the road, and getting maintenance on it is easy, as the wide majority of mechanics will be familiar with it. Sounds like your car is in the same boat as mine.
That you consider a 5 year old processor and a 14 year old car to be old is a reflection of your own opinions. I do not agree and think that perspective is consumerist, exactly what corporations spend lots of money to try and make people think.
[0]: https://ourworldindata.org/grapher/carbon-intensity-electric...
No one cares about how long you had the CPU in your possession, nor are we worried about the silicon expiring. If you restarted the factory line and got a brand new chip today, it would still be considered 5 years and 1 month old. Like finding a factory-sealed retro console.
> If the hardware can run just fine, what makes it old?
When something is "old" is context specific, related to how fast the world moves away from it.
To give some easily digestable examples:" A 1 year old person is very young, a 1-year old ant is very old. A 70-year old CEO is old, but might perform the best they ever have in their entire life. A 50-year old car is old, but fully compatible with modern roads and fuels (depending on spec). Despite no formal definition, these are quite objective in that no-one not playing devils advocate could possibly disagree.
For chips, they are old after 4-5 years because the chip world moves fast. This chip has been superseded many times (a great-grandparent at this point), is in the bargain bin as of late last year at somewhere between 1/3rd and 1/6th the price depending on ongoing sales as shops clear unwanted deprecated stock, and now does the work in more than twice the time and with more than twice the energy than the current product in its own line. No one would reasonably look at this side by side with the current offering and think "that's not old!".
(Note: Pre-Ryzen and Apple silicon, the "time to old" was longer because Intel's monopoly and laziness had caused complete stagnation within desktop CPU development, which is what we have grown sued to.)
Buying an old chip is done for the same reasons as buying an old car: If you don't really need it much, it also can't bring you a lot of value and so something something brand new won't mean much to you. Getting a bargain on something old and/or used is great. Whether it is a chip or a car, efficiency doesn't matter if its mostly off anyway. And just like any NES plays NES games as well as it did from day one, the old car if serviced still does the same job it did when it was new.
> It isn't "objectively" old. "Old" does not have an objective definition.
If you believed this, it would invalidate your entire line of argument that the chip (and your car) cannot be considered old as age cannot be classified and is irrelevant: considering the chip not old is therefore also wrong.
Considering that you are specifically attacking the idea of considering the old with the idea that their useful life should be longer, completely ignoring that I mention that devices can be used irrespective of their age, I do not think you actually believe that the age should not be classified. At the same time, if you did not think it was objective, your argument would have focused on saying it was subjective or context-specific rather than saying the classification was wrong.
> that perspective is consumerist, exactly what corporations spend lots of money to try and make people think.
That consumerism is also why the chip is a bargain and new chips are affordable, and the only argument for buying an EOL chip is price. Having any sort of used market for things that get better with time requires people to often buy new things and get rid of old things. Having new things be affordable for anyone requires a significant churn.
> a carbon emissions perspective ...
... is not relevant as I make it very clear that being old does not mean it needs to be replaced. Even if it ends its service life with you, a responsible person would sell it or give it away so someone else can use it instead of buying new.
That is exactly what I did a short time ago when I was building a PC and deciding on parts for it. I thought it seemed like a perfectly reasonable option, given that:
1. It was readily available
2. Many other people were building computers with it, or recommending it for builds
3. I judged that it would function well and be compatible with the other hardware in the PC
You are letting the pace at which a company releases new products define what makes something "old" to you. Even if the model that is several releases "old" came out 5 years ago, still functions well and can be used effectively with the software and hardware coming out right now.
It's "old" because the company has released newer versions? It's "old" because it's less expensive? And because it is "old", according to actions taken by the company, it should not be supported, or repaired if there is fault with it? This is clearly exactly what companies want from their consumers to extract as much money as possible from them, and a recipe for massive consumption.
> Buying an old chip is done for the same reasons as buying an old car: If you don't really need it much, it also can't bring you a lot of value and so something something brand new won't mean much to you.
I don't understand. I do need a car, and my car from 14 years ago provides me tons of value. As does my main laptop computer from 6 years ago. I need that computer to make my living doing programming and IT work, and it does a fantastic job of it.
> If you believed this, it would invalidate your entire line of argument that the chip (and your car) cannot be considered old as age cannot be classified and is irrelevant: considering the chip not old is therefore also wrong.
To not have an objective definition does not mean that it means nothing, it means it has a subjective definition. We are disagreeing on our subjective definitions of "old" in this context, and I am saying that your definition leads to negative effects.
> I do not think you actually believe that the age should not be classified. At the same time, if you did not think it was objective, your argument would have focused on saying it was subjective or context-specific rather than saying the classification was wrong.
Yes, I was saying that it has a subjective definition. I thought "does not have an objective definition" in this context implied "has a subjective definition", not "has no meaning and classification of age is impossible".
> That consumerism is also why the chip is a bargain and new chips are affordable, and the only argument for buying an EOL chip is price.
What about all the people who bought the chip at full price 4-5 years ago? They're SOL the same as I am. And I didn't think it was EOL, and don't think it should be. There's no official EOL in the sense "this is how long we'll support this desktop CPU for before it stops receiving security updates". The only reason to believe that it wouldn't receive an update to fix a vulnerability several months later would've been a hazy guess, were I more tuned in to the CPU market. I believe in consumer protection laws that mandate support of products and repair of serious flaws for a longer period.
In terms of reasons for not keeping up with the Joneses: carbon emissions, slowing consumption, keeping things from the junk pile. These are immensely important.
> is not relevant as I make it very clear that being old does not mean it needs to be replaced. Even if it ends its service life with you, a responsible person would sell it or give it away so someone else can use it instead of buying new.
This whole discussion is about a flaw in the chip that leaves a serious vulnerability open. The problem is that if you are risk-averse, or sensitive to cyberattacks, it does need to be replaced. And as the chip could be unsafe, it can't (safely) just be handed off to someone else to use.
This isn't about free updates or improvements. It's about fixing a fixable flaw that leaves open a serious vulnerability that enables persistent infection of a computer. Few people will be capable of making a proper assessment of the risk, even among devs and IT folk.
The CPUs are "old" they are "limit" as an installed base but only comparing to today's AMD market share because I'm pretty sure there are hundred of thousands ( if not a few millions ) of these CPUs all over the World.
My main point is: going the extra-mile/cost to fix these cpus would be the cheaper route for them because image and credibility matters.. a lot.
There are at least upgrade options compatible with the same socket, unlike a certain other CPU manufacturer, but it's not like these are really worth replacing yet.
UserBenchmark scores the 5800x3d about 17% higher for $340.
At minimum, save it toward a GPU upgrade that would actually be useful, rather than replacing my CPU that isn't a performance bottleneck.
http://en.m.wikipedia.org/wiki/Zen_2
That's not very old.
I guess maybe they can't fix them or something. This is very bad for their reputation.
As this bug now has become known to always have been there, i could probably force amd to replace my 3900x if they don't provide software patches.
Has anyone else attempted a similar RTM for software defects?
(Though in most EU/EEA countries you only get 2 years, which is why phones now get 36 months of security updates if they're on sale for 12 months).
Somebody with ring 0 privileges (a prereq for this) on your CPU already has root and you have to presume they've already had the ability to write to your BIOS and VBIOS, and this is just confirmation of that. If you're actually worried about this stuff then how can you be sure that someone hasn't paid Microsoft to put stuff into your firmware?
Edit after looking it up (leaving this comment in case someone else has the same question): Apparently microcode is in fact stored in the CPU itself and it does have permanent storage. The BIOS is only used for updating this internal memory and doesn’t transfer the microcode on every boot. I still wonder if the microcode patches are somehow validated/signed though, otherwise everyone with a kernel exploit could issue update commands to the BIOS with malicious microcode content?
It works even when there's no CPU installed.
How is a compromised AMD CPU better than Intel's CPUs which get damaged due to oxidation and high voltage?
>How is a compromised AMD CPU better than Intel's CPUs which get damaged due to oxidation and high voltage?
From a sibling comment:
>Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access
For the typical desktop scenario, this is a nothingaburger because it's already game over if malicious code can get any sort of access[1]. It might matter more for server providers because their customers can execute arbitrary ring0 code in guest VMs, but it's unclear whether it affects that or not.
Having security bugs isn't great, but in this case having hardware degradation leading to performance loss and/or crashing is much noticeable.
There's no valid reason to not have this law. Any "intellectual property" excuses aren't going to fly, everyone already knows they're bullshit.
edited: slightly clarified legal possession