Guru3D.com
  • HOME
  • NEWS
    • Channels
    • Archive
  • DOWNLOADS
    • New Downloads
    • Categories
    • Archive
  • GAME REVIEWS
  • ARTICLES
    • Rig of the Month
    • Join ROTM
    • PC Buyers Guide
    • Guru3D VGA Charts
    • Editorials
    • Dated content
  • HARDWARE REVIEWS
    • Videocards
    • Processors
    • Audio
    • Motherboards
    • Memory and Flash
    • SSD Storage
    • Chassis
    • Media Players
    • Power Supply
    • Laptop and Mobile
    • Smartphone
    • Networking
    • Keyboard Mouse
    • Cooling
    • Search articles
    • Knowledgebase
    • More Categories
  • FORUMS
  • NEWSLETTER
  • CONTACT

New Reviews
Razer Leviathan V2 gaming soundbar review
Guru3D NVMe Thermal Test - the heatsink vs. performance
EnGenius ECW220S 2x2 Cloud Access Point review
Alphacool Eisbaer Aurora HPE 360 LCS cooler review
Noctua NH-D12L CPU Cooler Review
Silicon Power XPOWER XS70 1TB NVMe SSD Review
Hyte Y60 chassis review
ASUS ROG Thor 1000W Platinum II (1000W PSU) review
ASUS ROG Rapture GT-AXE11000 WIFI6E router review
Backforce One Plus Gaming Chair review

New Downloads
CrystalDiskInfo 8.17 Download
AMD Radeon Software Adrenalin 22.6.1 Windows 7 driver download
ReShade download v5.2.2
HWiNFO Download v7.26
7-Zip v22.00 Download
GeForce 516.40 WHQL driver download
Intel ARC graphics Driver Download Version: 30.0.101.1736
AMD Radeon Software Adrenalin 22.5.2 WHQL driver download
Corsair Utility Engine Download (iCUE) Download v4.24.193
Intel HD graphics Driver Download Version: 30.0.101.1994


New Forum Topics
Collapse of crypto mining industry leads to auctioning off of thousands of graphics cards Info Zone - gEngines, Ray Tracing, DLSS, DLAA, TSR, FSR, XeSS, DLDSR etc. First SKU rumors for AMD Ryzen 7000 mobile AMD Radeon Software - UWP De-lidded AMD Ryzen 7 5800X3D Has Significant Thermal Improvements [3rd-Party Driver] Amernime Zone Radeon Insight 22.5.1 WHQL Driver Pack (Released) 3090 Owner's thread NVIDIA GeForce 516.40 WHQL driver download & Discussion We need to talk about UE4 Shader compilation issues GeForce GTX 1630 will launch on June 28




Guru3D.com » News » New CacheOut Speculative Execution Vulnerability Hits Intel Processors

New CacheOut Speculative Execution Vulnerability Hits Intel Processors

by Hilbert Hagedoorn on: 01/28/2020 04:34 PM | source: | 75 comment(s)
New CacheOut Speculative Execution Vulnerability Hits Intel Processors

Intel is not spared when it comes to the number of vulnerabilities that keep hitting their processors. The latest one is CacheOut, a new speculative execution attack that is capable of leaking data from Intel CPUs across many security boundaries. All processors up-to-the recent Coffee lake refresh are effected.

Despite Intel's attempts to address previous generations of speculative execution attacks, CPUs are still vulnerable, allowing attackers to exploit these vulnerabilities to leak sensitive data. Unlike previous MDS issues, the researchers show in their work how an attacker can exploit the CPU's caching mechanisms to select what data to leak, as opposed to waiting for the data to be available.

They then demonstrate that CacheOut can violate nearly every hardware-based security domain, leaking data from the OS kernel, co-resident virtual machines, and even SGX enclaves. CacheOut  can bypass software fixes. Making it possible to extract data from both the kernel of the OS and from virtual machines, and also from something that Intel calls 'software guard extensions' (SGX) that normally is stored securely. 

 

 

Researchers from the University of Michigan and the University of Adelaide have found this new bug, and posted a paper on it. Read the paper. It seems that once again only Intel processors are affected including Core, Xeon and Atom models. AMD is save from this vulnerability.



New CacheOut Speculative Execution Vulnerability Hits Intel Processors




« Review: PowerColor Radeon RX 5600 XT Red Dragon · New CacheOut Speculative Execution Vulnerability Hits Intel Processors · New Battlefield V chapter based on jungle fights in the Pacific Ocean Area »

15 pages « < 12 13 14 15


Cyberdyne
Senior Member



Posts: 3582
Joined: 2010-01-16

#5756028 Posted on: 01/31/2020 03:42 AM
Does it matter?
Imagine a hacker successfully injected malicious code (exploiting this or any other cache memory vulnerability) into some web page. And some user visited this page allowing hacker to monitor the cache memory reads and writes in real time (until user closed a browser). Do you think it will be easy for a hacker to understand what he sees? Is it even possible to view cache memory operations in real time? Hacker should actually store all the info (big amount - so the channel should be fast) to analyse afterwards, hoping that this dump of cache memory operations contains something useful.
Then no, it doesn't matter. None of it does. Do you see the point behind this exploit hysteria?

sverek
Senior Member



Posts: 6073
Joined: 2011-01-02

#5756030 Posted on: 01/31/2020 03:57 AM
Then no, it doesn't matter. None of it does. Do you see the point behind this exploit hysteria?

Yes, Intel can't design CPU with security in mind.
It's not about {insert exploit name here} is nearly impossible to reproduce in real-life situation. It's about Intel not paying attention to it.

"Under a certain condition your car brakes might not work, but it's nothing to worry about, since you drive your car as any normal person"

Fox2232
Senior Member



Posts: 11809
Joined: 2012-07-20

#5756089 Posted on: 01/31/2020 10:04 AM
sure, you have a strong bottleneck, its a worst sensation than a simple fps flutuation caused by gpu

Btw, youre confused about what vsync and freesync does
I am not confused about those technologies. That's unless you can specifically say what you disagree with and then correct it.
Because I am perfectly aware of all underlying timing functionalities of each technology.
And you may be surprised by fact that 100Hz Free/G-sync screen is incapable to display two consecutive frames in shorter interval than 10ms from each other. (Which creates another minor timing issue if you have average 100fps, but frametimes fluctuate. As frame has to wait till it can be shown for 1ms in situation where two consecutive frames came at 9ms interval.)

D1stRU3T0R
Senior Member



Posts: 580
Joined: 2017-08-16

#5756090 Posted on: 01/31/2020 10:05 AM
No, 2700x are completelly destroyed even the 3900x hardly you can see beating the 8700k

https://www.techpowerup.com/review/amd-ryzen-9-3900x/15.html

Are you comparing 2700X to the 3900X?

Different architecture, different tier lol. At least if you would compare 2700X to 3700X...and you are showing gaming benchmark, rly mate?

mbk1969
Senior Member



Posts: 12426
Joined: 2013-01-17

#5756126 Posted on: 01/31/2020 11:52 AM
Then no, it doesn't matter. None of it does. Do you see the point behind this exploit hysteria?


Trivial social media hype.

What I don`t understand is why browser can even execute low level CPU instructions (needed for such attacks) executing java-script? How? Why a script language can even emit low level CPU instructions?

15 pages « < 12 13 14 15


Post New Comment
Click here to post a comment for this news story on the message forum.


Guru3D.com © 2022