New $50 Battering RAM Attack Breaks Intel and AMD Cloud Security Protections (thehackernews.com)
from kid@sh.itjust.works to cybersecurity@sh.itjust.works on 02 Oct 19:16
https://sh.itjust.works/post/47188661

#cybersecurity

threaded - newest

solrize@lemmy.ml on 02 Oct 19:27 collapse

In case it’s not obvious, this is a hardware attack that lets someone with access to the motherboard (e.g. a cloud host) see what your VM is doing even if you use the CPU’s security features that are supposed to prevent that. Intel’s version (SGX) of that feature has been considered broken in other ways for years. Not sure about AMD’s but I’d expect about the same. Better not run super high security stuff on hardware controlled by an attacker :).

9point6@lemmy.world on 02 Oct 19:42 collapse

Any machine with which an attacker has had physical access to should be considered compromised

I don’t imagine trusting any countermeasure close to enough to invalidate that rule