Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Researchers Find Critical Security Flaws in AMD Chips
security week ^ | 3/13/2018 | AFP

Posted on 03/13/2018 1:53:20 PM PDT by bitt

Security researchers said Tuesday they discovered flaws in chips made by Advanced Micro Devices that could allow hackers to take over computers and networks.

Israeli-based security firm CTS Labs published its research showing "multiple critical security vulnerabilities and exploitable manufacturer backdoors" in AMD chips.

CTS itemized 13 flaws, saying they "have the potential to put organizations at significantly increased risk of cyberattacks."

The report comes weeks after Intel disclosed similar hardware-based flaws dubbed Meltdown and Spectre, sparking widespread computer security concerns and a congressional inquiry.

CTS said the newly discovered flaws could compromise AMD's new chips that handle applications in the enterprise, industrial and aerospace sectors, as well as consumer products.

In a 20-page white paper, the researchers said the AMD Secure Processor, the gatekeeper responsible for the security of AMD processors, contains "critical vulnerabilities" that "could allow malicious actors to permanently install malicious code inside the Secure Processor itself."

"These vulnerabilities could expose AMD customers to industrial espionage that is virtually undetectable by most security solutions," the researchers said.

CTS said AMD's Ryzen chipset, which AMD outsourced to a Taiwanese chip manufacturer, ASMedia, "is currently being shipped with exploitable manufacturer backdoors inside."

This could allow attackers "to inject malicious code into the chip" and create "an ideal target" for hackers, the researchers said.

"CTS believes that networks that contain AMD computers are at a considerable risk," the report said.

"The vulnerabilities we have discovered allow bad actors who infiltrated the network to persist in it, surviving computer reboots and reinstallations of the operating system.

(Excerpt) Read more at securityweek.com ...


TOPICS: Business/Economy; Extended News; Miscellaneous; News/Current Events
KEYWORDS: amdchips; securityflaws; windowspinglist
Navigation: use the links below to view more comments.
first 1-2021-27 next last

1 posted on 03/13/2018 1:53:20 PM PDT by bitt
[ Post Reply | Private Reply | View Replies]

To: bitt

Darn. AMD was my go-to for a MicroLeftist alternative.


2 posted on 03/13/2018 1:54:52 PM PDT by fwdude (History has no 'sides;' you're thinking of geometry.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce; dayglored; Swordmaker

PING


3 posted on 03/13/2018 1:55:57 PM PDT by bitt (The first to squeal gets the best deal.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: bitt

China and Taiwan have a very cozy business relationship.

I rather doubt all these back doors are accidental.

Make no mistake, this is an act of war.


4 posted on 03/13/2018 1:58:57 PM PDT by null and void (The difference between the democrats and the GOPe is the GOPe has a smaller fire under the frog pot.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: fwdude

As with most things computer-related, as a home/small business user I try to stay a couple steps behind the bleeding edge.

Might be a few nanoseconds pokier than the whiz bang kids, but stability is more important to me these days than bragging rights.


5 posted on 03/13/2018 2:00:31 PM PDT by tomkat
[ Post Reply | Private Reply | To 2 | View Replies]

To: null and void

“I rather doubt all these back doors are accidental.”

That is certainly true, and, to some extent, I agree (big brother needs to know everything about everyone).

However, processors are ridiculously complex these days (well, they were always ridiculous complex compared to the previous generation ... but I think you know what I mean) ... and they’re microcoded to allow field upgrades to fix bugs & performance issues. I’m sure they overlooked things be it on purpose or “for real” :-).


6 posted on 03/13/2018 2:09:03 PM PDT by edh
[ Post Reply | Private Reply | To 4 | View Replies]

To: tomkat

Same here.


7 posted on 03/13/2018 2:12:23 PM PDT by fwdude (History has no 'sides;' you're thinking of geometry.)
[ Post Reply | Private Reply | To 5 | View Replies]

To: bitt; Swordmaker; ShadowAce

AMD Ping!...................


8 posted on 03/13/2018 2:14:46 PM PDT by Red Badger (The people who call Trump a tyrant are the same people who want the president to confiscate weapons.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: null and void

Once is an accident.
Twice is a coincidence.
Three times is an act of war...............


9 posted on 03/13/2018 2:15:50 PM PDT by Red Badger (The people who call Trump a tyrant are the same people who want the president to confiscate weapons.)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Red Badger

This is about the Ryzen chip so far, so my old AMD will probably be OK.


10 posted on 03/13/2018 2:17:48 PM PDT by VanShuyten ("...that all the donkeys were dead. I know nothing as to the fate of the less valuable animals.")
[ Post Reply | Private Reply | To 8 | View Replies]

To: bitt

If we had high enough import tariffs, AMD wouldn’t be offshoring the production of these chips.


11 posted on 03/13/2018 2:21:53 PM PDT by DannyTN
[ Post Reply | Private Reply | To 1 | View Replies]

To: bitt

So the Chinese added a back door into the chip? Shocking.

If Trump cared about national security, he’d put a tariff on foreign chips, not moving to protect the self serving management at Qualcomm at the expense of shareholders.


12 posted on 03/13/2018 2:23:37 PM PDT by PAR35
[ Post Reply | Private Reply | To 1 | View Replies]

To: null and void
". . .I rather doubt all these back doors are accidental."

From the article :
". . . manufacturer backdoors"

Right there at least some of them are fingered as having been left deliberately by AMD themselves. The question is, were incentives or threats used by US Intelligence to put those back doors in and if it's 'neither', then why did AMD put them into the design.

13 posted on 03/13/2018 2:35:50 PM PDT by Rashputin (Jesus Christ doesn't evacuate His troops, He leads them to victory !!)
[ Post Reply | Private Reply | To 4 | View Replies]

Thanks so much for your support to this point... I personally apprecaite it...
FReepers, it's far beyond time to wrap up this FReep-a-thon.  Lets do it today.  Please chip in.


President Donald J. Trump and the Free Republic of the United States of America
President Donald J. Trump's address to the United Nations on 09/19/2017.

Ramirez political cartoon:  Trade War LARGE VERSION 03/12/2018: LINK  LINK to regular sized versions of his political cartoons (archive).
Garrison political cartoon:  Gun Control Supporters LARGE VERSION 03/13/2018: LINK  LINK (scroll down) to regular sized versions of his political cartoons (archive).




FReepers, 87.788% of the Third Quarter FReep-a-thon goal has been met.  Click above and pencil in your donation now.  Please folks, lets end this FReepathon.  Thank you!

...this is a general all-purpose message, and should not be seen as targeting any individual I am responding to...

Just $187.00 dollars to 88.00%

14 posted on 03/13/2018 3:07:57 PM PDT by DoughtyOne (01/26/18 DJIA 30 stocks $26,616.71 48.794% > open 11/07/16 215.71 from 50% increase 1.2183 yrs..)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Rashputin
The question is, were incentives or threats used by US Intelligence to put those back doors in and if it's 'neither', then why did AMD put them into the design.

Neither since it is easy to insert a human asset into the design team. The real question is whether the US and Chinese intelligence cooperated on the back door so they could both use it, or whether one or the other did it alone.

15 posted on 03/13/2018 3:22:27 PM PDT by palmer (...if we do not have strong families and strong values, then we will be weak and we will not survive)
[ Post Reply | Private Reply | To 13 | View Replies]

To: bitt

Didn’t AMD move its production to some communist run country?


16 posted on 03/13/2018 3:51:51 PM PDT by fella ("As it was before Noah so shall it be again,")
[ Post Reply | Private Reply | To 1 | View Replies]

To: bitt

The white paper presents 4 attack vectors:

MasterKey
RyzenFall
Fallout
Chimera

MasterKey requires the ability to alter the BIOS

The other three require administrator privileges to exploit.

Chimera is the most dangerous in my mind as it is a chip / asic level error.

All four will require significant rework of the product line to fix.

Kind of crappy that CTS did not allow AMD the normal courtesy of 90 days notice before releasing the white paper.


17 posted on 03/13/2018 4:02:03 PM PDT by taxcontrol (Stupid should hurt)
[ Post Reply | Private Reply | To 1 | View Replies]

To: fella

“CTS said AMD’s Ryzen chipset, which AMD outsourced to a Taiwanese chip manufacturer, ASMedia, “is currently being shipped with exploitable manufacturer backdoors inside.””

wonder if my old pc chip is ok...


18 posted on 03/13/2018 4:03:19 PM PDT by bitt (The first to squeal gets the best deal.)
[ Post Reply | Private Reply | To 16 | View Replies]

To: bitt; Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; amigatec; AppyPappy; arnoldc1; ...
AMD flaws, maybe ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

Thanks to bitt for the ping!


Frankly, color me somewhat skeptical of this report.

https://amdflaws.com/disclaimer.html:

"The report and all statements contained herein are opinions of CTS and are not statements of fact... You are advised that we may have, either directly or indirectly, an economic interest in the performance of the securities of the companies whose products are the subject of our reports..."
AND

A comment from Reddit's /r/netsec:

"...Looking closer a PR firm CEO is directly handling media for this small, recently formed Israeli company. The Israeli company CEO has experience selling off sec-tech firms to others. The PR firm put out a press release/article last year (when they themselves were founded from past careers in NYC venture/hedge funds) about how they understand how venture capital uses big data to identify opportunities and they connect those opportunities to capital. Could be Intel...but I'm thinking its just as likely this is a PR based pump-n-dump play in a hot sector."
Add to that the fact that they didn't give the usual 90 days advance warning...

Color me VERY skeptical.

19 posted on 03/13/2018 6:11:35 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 3 | View Replies]

To: taxcontrol
> Kind of crappy that CTS did not allow AMD the normal courtesy of 90 days notice before releasing the white paper.

VERY crappy. I suspect this could be BS meant to affect stock prices, little or nothing more.

20 posted on 03/13/2018 6:13:07 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 17 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-27 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson