After being shocked by the "Spectre" and "Meltdown" side-channel attack vulnerabilities that affected modern Intel, AMD and ARM processors in 2017, security researchers have now exposed a more advanced vulnerability that uses CPU boost frequencies to steal encryption keys - it is Hertzbleed.
(Source: Hertzbleed website)
The attack works by monitoring the power signature of any cryptographic workload for a side-channel vulnerability, and like everything else in a CPU, processor power adjusts as workloads change.
But after observing this power information, the Hertzbleed attacker can convert it into timing data and steal the encryption keys of the user process.
● Currently, both Intel and AMD have announced systems that are vulnerable to the Heartzbleed vulnerability attack, which affects the entire Intel series and AMD Zen 2 / Zen 3 processors.
● The former was assigned the vulnerability IDs Intel-SA-00698 and CVE-2022-24436, while the latter was CVE-2022-23823.
Principle diagram (Image from: Intel website)
Worse still, the Hertzbleed vulnerability can be exploited remotely without the need for an attacker to have physical access to the device.
The two chip companies will then provide microcode-based patch mitigations to prevent such vulnerabilities from being further exploited by attackers.
Fortunately, Intel claims that such attacks are not very practical outside of laboratory research, as stealing encryption keys is said to take hours to days.
As for the CPU performance loss that may be caused by the vulnerability patch, it still depends on the specific application scenario.
Previous article:Self-developed chips may revitalize Apple's Mac computers and Microsoft's Windows cash cow may be threatened
Next article:The 6th Intel Grandmasters Challenge has been upgraded to a professional level, and the winners will be sent to the League of Legends Youth Training Camp
- Popular Resources
- Popular amplifiers
- Innovation is not limited to Meizhi, Welling will appear at the 2024 China Home Appliance Technology Conference
- Enjoy big-screen gaming anytime, anywhere: Making portable 4K UHD 240Hz gaming projector a reality
- AMD surpasses Intel: CPU shipments surge in Q3 this year
- Exynos is losing ground, Samsung plans to use Qualcomm chips in home appliances
- Intel and 50 partners unveiled a full range of 30 notebook and desktop AI PCs equipped with Intel Core Ultra (2nd Generation)
- Innovation leads the new trend of mobile refrigeration GMCC will present new products at 2024 CIAAR
- Lenovo and NVIDIA expand collaboration to jointly launch new liquid-cooled AI servers
- Ceiling fan solution based on XMC1302
- Gartner: Global AI PC shipments are expected to account for 43% of total PC shipments in 2025
- LED chemical incompatibility test to see which chemicals LEDs can be used with
- Application of ARM9 hardware coprocessor on WinCE embedded motherboard
- What are the key points for selecting rotor flowmeter?
- LM317 high power charger circuit
- A brief analysis of Embest's application and development of embedded medical devices
- Single-phase RC protection circuit
- stm32 PVD programmable voltage monitor
- Introduction and measurement of edge trigger and level trigger of 51 single chip microcomputer
- Improved design of Linux system software shell protection technology
- What to do if the ABB robot protection device stops
- Ranking of installed capacity of smart driving suppliers from January to September 2024: Rise of independent manufacturers and strong growth of LiDAR market
- Industry first! Xiaopeng announces P7 car chip crowdfunding is completed: upgraded to Snapdragon 8295, fluency doubled
- P22-009_Butterfly E3106 Cord Board Solution
- Keysight Technologies Helps Samsung Electronics Successfully Validate FiRa® 2.0 Safe Distance Measurement Test Case
- Innovation is not limited to Meizhi, Welling will appear at the 2024 China Home Appliance Technology Conference
- Innovation is not limited to Meizhi, Welling will appear at the 2024 China Home Appliance Technology Conference
- Huawei's Strategic Department Director Gai Gang: The cumulative installed base of open source Euler operating system exceeds 10 million sets
- Download from the Internet--ARM Getting Started Notes
- Learn ARM development(22)
- Learn ARM development(21)
- The document issued by the Ministry of Industry and Information Technology is expected to drive new demand for new energy vehicle related testing instruments
- Chengdu is raging again. When will it end?
- CircuitPython Application Menu Launcher
- LC resonance
- Tektronix Jianghu Ling: Complaining and sharing the development of USB Type-C, collecting energy and growing together
- Raspberry Pi LED Cube Kit LumiCube in crowdfunding
- 【Iprober 520 Current Probe】Evaluation Report (I) Principle Specifications and Preliminary Impressions
- 【Silicon Labs BG22-EK4108A Bluetooth Development Review】 3. LED flashing
- Modified +2A boost board circuit analysis
- DC-DC Converter Circuit Design