Zen and the Art of Microcode Hacking (bughunters.google.com)
from tedu@inks.tedunangst.com to inks@inks.tedunangst.com on 08 Mar 06:03
https://inks.tedunangst.com/l/5183

In this post, we first discuss the background of what microcode is, why microcode patches exist, why the integrity of microcode is important for security, and how AMD attempts to prevent tampering with microcode. Next, we focus on the microcode patch signature validation process and explain in detail the vulnerability present (using CMAC as a hash function). Finally, we discuss how to use some of the tools we’ve released today which can help researchers reproduce and expand on our work (skip to the Zentool section of this blogpost for a “how to” on writing your own microcode).

#bios #cpu #exploit #hash #programming #security #systems

#bios #cpu #exploit #hash #inks #programming #security #systems

threaded - newest