Slashdot: Hardware's Journal
 
[Most Recent Entries] [Calendar View]

Saturday, October 19th, 2024

    Time Event
    4:34p
    Spectre Flaws Still Haunt Intel, AMD as Researchers Found Fresh Attack Method
    "Six years after the Spectre transient execution processor design flaws were disclosed, efforts to patch the problem continue to fall short," writes the Register: Johannes Wikner and Kaveh Razavi of Swiss University ETH Zurich on Friday published details about a cross-process Spectre attack that derandomizes Address Space Layout Randomization and leaks the hash of the root password from the Set User ID (suid) process on recent Intel processors. The researchers claim they successfully conducted such an attack.... [Read their upcomong paper here.] The indirect branch predictor barrier (IBPB) was intended as a defense against Spectre v2 (CVE-2017-5715) attacks on x86 Intel and AMD chips. IBPB is designed to prevent forwarding of previously learned indirect branch target predictions for speculative execution. Evidently, the barrier wasn't implemented properly. "We found a microcode bug in the recent Intel microarchitectures — like Golden Cove and Raptor Cove, found in the 12th, 13th and 14th generations of Intel Core processors, and the 5th and 6th generations of Xeon processors — which retains branch predictions such that they may still be used after IBPB should have invalidated them," explained Wikner. "Such post-barrier speculation allows an attacker to bypass security boundaries imposed by process contexts and virtual machines." Wikner and Razavi also managed to leak arbitrary kernel memory from an unprivileged process on AMD silicon built with its Zen 2 architecture. Videos of the Intel and AMD attacks have been posted, with all the cinematic dynamism one might expect from command line interaction. Intel chips — including Intel Core 12th, 13th, and 14th generation and Xeon 5th and 6th — may be vulnerable. On AMD Zen 1(+) and Zen 2 hardware, the issue potentially affects Linux users. The relevant details were disclosed in June 2024, but Intel and AMD found the problem independently. Intel fixed the issue in a microcode patch (INTEL-SA-00982) released in March, 2024. Nonetheless, some Intel hardware may not have received that microcode update. In their technical summary, Wikner and Razavi observe: "This microcode update was, however, not available in Ubuntu repositories at the time of writing this paper." It appears Ubuntu has subsequently dealt with the issue. AMD issued its own advisory in November 2022, in security bulletin AMD-SB-1040. The firm notes that hypervisor and/or operating system vendors have work to do on their own mitigations. "Because AMD's issue was previously known and tracked under AMD-SB-1040, AMD considers the issue a software bug," the researchers explain. "We are currently working with the Linux kernel maintainers to merge our proposed software patch." BleepingComputer adds that the ETH Zurich team "is working with Linux kernel maintainers to develop a patch for AMD processors, which will be available here when ready."

    Read more of this story at Slashdot.

    10:57p
    After Second Power Outage, 10 Million Cubans Endure Saturday Afternoon Blackout
    The Miami Herald reports: Cuba's electrical grid shut down again early Saturday, leaving the island without electricity after authorities tried but failed to restore power following an earlier nationwide blackout on Friday. The island's Electric Union reported a second "total outage" at 6:15 a.m., just hours after officials reported they had restored power in a few "microsystems" all over the island... The country has been going through its worst economic crisis since the fall of the Soviet Union, and the government lacks money to buy oil in the international market to meet domestic demand. Cubans irked by the daily blackouts defied the country's Draconian laws punishing criticism of the government and left several comments in official news outlets calling for government officials to resign. The second outage will likely exacerbate public frustration as food begins to spoil because of the lack of refrigeration. Two hours ago, Reuters reported that Cuba's government "said on Saturday it had made some progress in gradually re-establishing electrical service across the island, including to hospitals and parts of the capital Havana..." "Most of Cuba's 10 million people, however, remained without electricity on Saturday afternoon." Traffic lights were dark at intersections throughout Havana, and most commerce was halted... Cuban officials have said even if the immediate grid collapse is resolved, the electricity crisis will continue. Cuba produces little of its own crude oil, and fuel deliveries to the island have dropped significantly this year, as Venezuela, Russia and Mexico, once important suppliers, have reduced their exports to Cuba. Mexico experienced a historic drop in production, according to the New York Times, while Venezuela is selling its oil to foreign companies to ease its own economic crisis: The experts had warned for years: Cuba's power grid was on the verge of collapse, relying on plants nearly a half-century old and importing fuel that the cash strapped Communist government could barely afford... Cuban economists and foreign analysts blamed the crisis on several factors: the government's failure to tackle the island's aging infrastructure; the decline in fuel supplies from Venezuela, Mexico and Russia; and a lack of capital investment in badly needed renewable systems, such as wind and solar. Jorge Piñon, a Cuban-born energy expert at the University of Texas at Austin, highlighted that Cuba's electricity grid relies on eight very large power plants that are close to 50 years old. "They have not received any operational maintenance much less capital maintenance in the last 12 to 15 years," he said, adding that they have a lifetime of only 25-30 years. "So, number one, it's a structural problem, they are breaking down all the time and that has a domino effect," he said. Compounding the problems, Cuba burns crude oil as a fuel for its plants. Experts said Cuba's own crude oil production is very heavy in sulfur and metals that can impair the thermoelectric combustion process. "So they have to be constantly repairing them, and they're repairing them with Band-Aids," said Mr. Piñon... "If they can't turn these plants back on there is a concern that this could turn into another mass exodus," said Ricardo Herrero, the director of the Cuba Study Group in Washington. "They are really short on options," he added.

    Read more of this story at Slashdot.

    << Previous Day 2024/10/19
    [Calendar]
    Next Day >>

Slashdot: Hardware   About LJ.Rossia.org