AMD Epyc CPUs have a flaw that exposes the Secure Processor under virtualization

Published by

Click here to post a comment for AMD Epyc CPUs have a flaw that exposes the Secure Processor under virtualization on our message forum
https://forums.guru3d.com/data/avatars/m/248/248994.jpg
ability to modify the read-only memory (ROM) input voltage in the secure processor's bootloader.
So, the flaw allows frying the ROM within and thus basically permamently bricking the whole CPU?
https://forums.guru3d.com/data/avatars/m/273/273678.jpg
exploits that require physical access and electrical modification of the part aren't exploits at all.
https://forums.guru3d.com/data/avatars/m/166/166907.jpg
Astyanax:

exploits that require physical access and electrical modification of the part aren't exploits at all.
May as well smash it with a hammer, light it on fire or pour water on it at that point.
https://forums.guru3d.com/data/avatars/m/246/246171.jpg
This is kind of like saying iris/retinal scanners aren't secure because you can spoon out the eye of someone who has access and show that to the camera. Sure, it's not failproof, but I'm sure even AMD themselves could have told you "if you modify the motherboard and intercept the sensor with your own chip, you can circumvent the security". There are much simpler and less error-prone ways to hack a computer you have physical access to.
Kaarme:

So, the flaw allows frying the ROM within and thus basically permamently bricking the whole CPU?
Seems to me it's just overriding the voltage sensor; I don't think it would brick anything, so long as you didn't screw it up.
data/avatar/default/avatar08.webp
Physical presence needed. Meh
https://forums.guru3d.com/data/avatars/m/258/258688.jpg
Can't imagine why this is a "flaw"...if that's all they could find then the CPUs are practically invulnerable from remote attack, which is the desired state...;) If you have physical access to a machine then everything there becomes vulnerable.
https://forums.guru3d.com/data/avatars/m/56/56686.jpg
This is getting stupid all this firms look for ways
https://forums.guru3d.com/data/avatars/m/250/250418.jpg
tsunami231:

This is getting stupid all this firms look for ways
They are perusing fame! or being paid to do so.
https://forums.guru3d.com/data/avatars/m/189/189980.jpg
Physical direct access to the computer running corporate software is a security breach in itself. Wondering how this news would be received from Intel. Would people react the same or worse? I mean, no chip manufacturer is anyone's friend. An vulnerability is a vulnerability. But we should take the information with some precautions and some salt. I wonder if anyone managed to get inside a data center or a real server room. Leaving Hollywood and crappy movies aside, things aren't so simple to get even to the door.
https://forums.guru3d.com/data/avatars/m/34/34585.jpg
TBH if you need physical access, it's been approved by upper management under a change order request it's been recorded and the person has been vetted to be allowed access to the data centre and is on CCTV, the car is recorded timestamp is recorded. If you managed to get through all that any hardware is vulnerable with a long log of when you got to site what's been done, how long what was done and the list goes on and on. With some data centres, you are also escorted by security, the amount of paperwork that's required typically takes a lot longer to do than what actually needs to be done everything is scrutinised. Besides, 99.999999% of hackers will not physically put themselves in such a position, they would rather do it without being seen let alone leaving a long paper trail.
https://forums.guru3d.com/data/avatars/m/156/156348.jpg
Dazz:

Besides, 99.999999% of hackers will not physically put themselves in such a position, they would rather do it without being seen let alone leaving a long paper trail.
What about Tom Cruise?
https://forums.guru3d.com/data/avatars/m/34/34585.jpg
MonstroMart:

What about Tom Cruise?
He's part of the 0.0000001%
data/avatar/default/avatar01.webp
MonstroMart:

What about Tom Cruise?
he doesn't reach the rack security lock.