Security News Researchers warn of new Hyper-Threading-based Intel CPU vulnerability (dubbed TLBleed)

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Feb 4, 2016
2,520
And Intel is refusing to patch it

What just happened? Researchers at the Systems and Network Security Group at Vrije Universiteit Amsterdam say they have discovered yet another critical flaw in Intel’s processors. Unlike Spectre and Meltdown, it doesn’t rely on speculative execution but instead exploits the company’s Hyper-Threading tech. Intel, however, won’t be issuing any patches.

As reported by The Register, the new side-channel vulnerability on hyperthreaded CPUs has been dubbed TLBleed as it uses a processor’s translation lookaside buffer (TLB), a type of cache that holds mappings from virtual memory addresses to physical memory addresses.

TLBleed is exploited through Intel’s Hyper-Threading. When this technology is enabled, each core can execute multiple threads—generally two—simultaneously. These threads share resources inside the core, including memory caches and TLB.

When two programs are running in the same core, it’s possible for one of the threads to spy on the other thread by examining how it accesses the CPU’s private resources. “From these observations, it is possible to determine the contents of RAM secret to that other program,” explains The Register.

Researchers say they were able to use TLBleed to extract cryptography keys from another running program in 99.8 percent of tests on an Intel Skylake Core i7-6700K. Tests using other types of Intel processors had similarly high success rates.

Most users have little to worry about from TLBleed. Exploiting it requires either malware first being installed on a system, or a malicious user gaining access. And there’s still no evidence of the exploit being used in the wild.

"Don't panic: while a cool attack, TLBleed is not the new Spectre," said researcher Ben Gras.
 

SHvFl

Level 35
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Nov 19, 2014
2,346
So lets see. Intel doesn't want to pay them but the article didn't bother to ask Intel why they are not paying neither got the reason that the researchers were given. That is one bad way to write an article i must say because there must be 100% a reason why they are not getting paid. Intel didn't just wake up today and said no i am not paying these people but i will pay the next.
Basically, the article is terrible. Read this instead as the author put some more effort into it.
Hyperthreading under scrutiny with new TLBleed crypto key leak
 
F

ForgottenSeer 58943

The news just keeps getting worse for Intel of Israel.

Intelligent folks have already moved on from Intel after their gross betrayals. Remember, Unit8200 OFTEN bragged they were 15 years ahead of everyone else in electronic espionage. That statement has largely been attributed to the fact that Israeli's took over all R&D for Intel chips back in the late 1990's and since then have inserted a wide range of backdoors into Intel products.
 

Hi Brothers

Level 2
Verified
Apr 19, 2018
71
OpenBSD has already disabled intel hyper threading at OS level due to security concerns. It seems intel needs some worthy nicknames. Spectre & meltdown may be just d tip of the ice-berg.

Yeah why not just halve the performance of your CPU :LOL:

Look's like it is time to move on to AMD's more frequently, and to slowly replace all my Intel product's

But muh 10% extra fps in games
 
F

ForgottenSeer 58943

Look's like it is time to move on to AMD's more frequently, and to slowly replace all my Intel product's

Way ahead of you there bro.

Last year I boxed up a dozen Lenovo Yoga/Twist/Carbon notebooks and sold them off and replaced them with ARM powered Chromebooks. My last intel desktop was replaced with a Ryzen, which I like much better. I purged Intel from my home - bottom up and will never buy their stuff again.

The good part is, Meltdown fiasco happened around the time the house was due for a refresh on systems so it was all going to happen anyway. This just guaranteed Intel was going to make a quick exit. I've heard 'rumors' of backdoors in Intel stuff dating back to the early 2000's. Virtually every rumor I attributed to overly paranoid IT Engineers has born fruit. One even reached out to me and said 'Bro I told you so, Israel spies on everyone and backdoors anything they touch'.

Intel's CEO Brian 'Intel is an Israeli Company' Krzanich quit too, just ahead of this latest huge disclosure, but not before he sold all of that stock.
 
F

ForgottenSeer 69673

But ARM and AMD mere also effected bot those two, Spectre & meltdown so what is your point?
 
  • Like
Reactions: vtqhtr413
F

ForgottenSeer 58943

But ARM and AMD mere also effected bot those two, Spectre & meltdown so what is your point?

Intel is impacted by ALL of this crap.. Depending on ARM, it's not impacted, for example the Mediatek Arm's on my Chromebooks were never Meltdown/Spectre vulnerable. AMD doesn't appear to be impacted by TLBleed. The reality is, you're better off with AMD, and WAY better off with ARM.

https://www.itwire.com/security/833...w-intel-bug-will-need-ton-of-work-to-fix.html
 
F

ForgottenSeer 72227

This is getting insane, it seems like everyday there's a new vulnerability regarding Intel and not a small one at that. As bad as Meltdown and Spectre are, I'm glad in a way this has come to light. We now have many researchers poking around and uncovering all this stupidity.Day by day, Intel's reputation dwindling faster and faster. I for one will continue to use my current devices, however as they need replacement, they will be replaced with AMD and or ARM.
 
F

ForgottenSeer 58943

Also note

Realize that this vuln impacts a lot of your data, where it is stored. For example the server storing your password database is on a HyperV, and is using Translation Lookaside Buffer. In effect, your cloud data could be compromised.

So this isn't just about your desktop or laptop, it's about where your data is stored and how it is secured. It's time to rethink our data where it exists outside of our systems and how it's being impacted because you can bet your data is stored on a stack of poweredge's somewhere, and they are running intel chips.

I'm thinking of moving to Stateless Passwords and being done storing secured data offsite. It's too risky anymore.
 

Vasudev

Level 33
Verified
Nov 8, 2014
2,230
OpenBSD has already disabled intel hyper threading at OS level due to security concerns. It seems intel needs some worthy nicknames. Spectre & meltdown may be just d tip of the ice-berg.
Indeed they have. We as consumers must get these exploitable devices replaced free of cost.
Look's like it is time to move on to AMD's more frequently, and to slowly replace all my Intel product's
If AMD Ryzen Desktop chip was in laptops paired with GTX MXM I'd have moved so far there's only Intel+Nvidia.
My CPU perf. is absolute disaster after spectre microcode patch. So disabling HT will kill Intel's CPU share in Consumer,Prosumer, Enterprise and Cloud service providers.
 

DeepWeb

Level 25
Verified
Top Poster
Well-known
Jul 1, 2017
1,396
Ok so wth did Intel actually finally acknowledge the risks of HT because I found a security advisory regarding a similar exploit on HP's support page and they said disabling HT was one of the solutions which sounds absolutely ridiculous.

HPSBHF03590 rev. 2 - L1 Terminal Fault (L1TF) | HP® Customer Support

Analysis and mitigation of L1 Terminal Fault (L1TF)

They recommend safe scheduling of sibling logical processors
evOLcsor.png


This should also be able to address TLBleed and it was one of the main reasons why I upgraded to 1809 despite the bugs. I had a feeling that Microsoft patched the kernel and it seems like they did. As long as Windows and your favorite browser, password manager, AV/security suite and VPN follow this advice we should be fine, no?

The only way to absolutely be sure would be a separate processor that handles keys like in the iPhone good luck with that on PCs... Apple could probably smell the BS from miles away and they did the investment a long time ago.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top