1 min read

Researchers Find New CPU Security Vulnerability

Remember the Heartbleed scare we had a couple years back?  It was a nasty side-channel attack that was somewhat exotic and difficult to pull off, and it was absolutely devastating and sent shockwaves through the entire world.

Well, it’s back. In a way.

While this new side-channel attack isn’t identical, it’s similar enough that the researchers who discovered it gave it a similar sounding name:  Hertzbleed.  It allows remote attackers to pilfer full cryptographic keys by observing variations in CPU frequency enabled by dynamic voltage and frequency scaling, or DVFS for short.

In other words, hackers can monitor the electrical output of your PC and based on that, derive your cryptographic keys.

A team from the University of Texas at Austin, in collaboration with others from the University of Washington and the University of Illinois Urbana-Champaign are credited with the discovery of the new attack vector.

The team had this to say about their discovery:

“In the worst case, these attacks can allow an attacker to extract cryptographic keys from remote servers that were previously believed to be secure. [..] Hertzbleed is a real, and practical, threat to the security of cryptographic software.

First, Hertzbleed shows that on modern x86 CPUs, power side-channel attacks can be turned into (even remote!) timing attacks–lifting the need for any power measurement interface.

Second, Hertzbleed shows that, even when implemented correctly as constant time, cryptographic code can still leak via remote timing analysis.”

To Put Things in Perspective

To be fair, this is an incredibly exotic attack that would be extremely difficult for even the most experienced hackers in the world to pull off.  Even so, there are hackers out there in the world who have the skills to do this. That is why it’s somewhat disturbing that neither Intel nor AMD have any plans to issue a fix for the issues that make Hertzbleed possible.

Per an Intel spokesman:

“While this issue is interesting from a research perspective, we do not believe this attack to be practical outside of a lab environment.”

While that’s true, hackers have always been known for being more interested in bragging rights than practicality. In our view, it’s just a matter of time before we see Hertzbleed in the headlines.

Used with permission from Article Aggregator

Beyond the Cloud: Architecting Edge-Native IT for Real-Time Speed

Beyond the Cloud: Architecting Edge-Native IT for Real-Time Speed

The speed of light is fast, but is it fast enough for your business? In the era of hyper-connectivity, we have grown accustomed to the cloud as the...

Read More
Unified IT and the Rise of Connected Business

Unified IT and the Rise of Connected Business

Remember the days of Rolodexes, filing cabinets, and interoffice memos? Each department had its own system, its own language, its own little kingdom....

Read More
Mind the Gaps: A Law Firm's Guide to Modern Data Protection

Mind the Gaps: A Law Firm's Guide to Modern Data Protection

In the legal world, data is everything. It's the evidence, the case files, the client communications...it's the lifeblood of your practice. So, what...

Read More

Employee Information Was Leaked At Cookware Company Meyer

Meyer Corporation is a California-based company and a giant in the cookware industry. Meyer is the latest victim in a seemingly never-ending parade...

Read More

The Rising Threat of Cyber Attacks: A Modern Challenge

Cyber threats have transformed significantly over the years, progressing from basic spyware in the early 2000s to today’s sophisticated attacks that...

Read More

Ransomware Attack Wreaks Havoc On Prison Employees And Inmates

Chalk up another first for the hackers. For the first time that we know of, a successful hacking attack caused prisoners in New Mexico to be confined...

Read More