Page 1 of 1

New Intel CPU Flaw Exploits Hyper-Threading to Steal Encrypted Data

Posted: Sun Nov 04, 2018 7:11 pm
by colin_b
https://thehackernews.com/2018/11/ports ... ility.html

A team of security researchers has discovered another serious side-channel vulnerability in Intel CPUs that could allow an attacker to sniff out sensitive protected data, like passwords and cryptographic keys, from other processes running in the same CPU core with simultaneous multi-threading feature enabled.

The vulnerability, codenamed PortSmash (CVE-2018-5407), has joined the list of other dangerous side-channel vulnerabilities discovered in the past year, including Meltdown and Spectre, TLBleed, and Foreshadow.

...

The simple fix for the PortSmash vulnerability is to disable SMT/Hyper-Threading in the CPU chip's BIOS until Intel releases security patches. OpenSSL users can upgrade to OpenSSL 1.1.1 (or >= 1.1.0i if you are looking for patches).

Re: New Intel CPU Flaw Exploits Hyper-Threading to Steal Encrypted Data

Posted: Sun Nov 04, 2018 7:21 pm
by handy

Re: New Intel CPU Flaw Exploits Hyper-Threading to Steal Encrypted Data

Posted: Sun Nov 04, 2018 7:38 pm
by colin_b
handy wrote: Sun Nov 04, 2018 7:21 pm More here: viewtopic.php?f=6&t=46809
I missed that :embarrassed:

Re: New Intel CPU Flaw Exploits Hyper-Threading to Steal Encrypted Data

Posted: Mon Nov 05, 2018 6:25 am
by handy
colin_b wrote: Sun Nov 04, 2018 7:38 pm
handy wrote: Sun Nov 04, 2018 7:21 pm More here: viewtopic.php?f=6&t=46809
I missed that :embarrassed:
It is easily done. ;)