{"id":1237273,"date":"2025-03-05T17:10:45","date_gmt":"2025-03-05T22:10:45","guid":{"rendered":"https:\/\/www.prime-wow.com\/?p=1237273"},"modified":"2025-03-05T17:10:45","modified_gmt":"2025-03-05T22:10:45","slug":"zen-and-the-art-of-microcode-hacking-google-bug-hunters","status":"publish","type":"post","link":"https:\/\/www.prime-wow.com\/?p=1237273","title":{"rendered":"Zen and the Art of Microcode Hacking (Google Bug Hunters)"},"content":{"rendered":"<div>The Google Bug Hunters blog has <a href=\"https:\/\/bughunters.google.com\/blog\/5424842357473280\/zen-and-the-art-of-microcode-hacking\">a<br \/>\ndetailed description<\/a> of how a vulnerability in AMD&#8217;s microcode-patching<br \/>\nfunctionality was discovered and exploited; the authors have also released<br \/>\na set of tools to assist with this kind of research in the future.<\/p>\n<blockquote class=\"bq\"><p>\n\tSecure hash functions are designed in such a way that there is no<br \/>\n\tsecret key, and there is no way to use knowledge of the<br \/>\n\tintermediate state in order to generate a collision. However, CMAC<br \/>\n\twas not designed as a hash function, and therefore it is a weak<br \/>\n\thash function against an adversary who has the key. Remember that<br \/>\n\tevery AMD Zen CPU has to have the same AES-CMAC key in order to<br \/>\n\tsuccessfully calculate the hash of the AMD public key and the<br \/>\n\tmicrocode patch contents. Therefore, the key only needs to be<br \/>\n\trevealed from a single CPU in order to compromise all other CPUs<br \/>\n\tusing the same key. This opens up the potential for hardware<br \/>\n\tattacks (e.g., reading the key from ROM with a scanning electron<br \/>\n\tmicroscope), side-channel attacks (e.g., using Correlation Power<br \/>\n\tAnalysis to leak the key during validation), or other software or<br \/>\n\thardware attacks that can somehow reveal the key. In summary, it is<br \/>\n\ta safe assumption that such a key will not remain secret forever.\n<\/p><\/blockquote>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>The Google Bug Hunters blog has a detailed description of how a vulnerability in AMD&#8217;s microcode-patching functionality was discovered and exploited; the authors have also released a set of tools to assist with this kind of research in the future. &hellip; <a href=\"https:\/\/www.prime-wow.com\/?p=1237273\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":""},"categories":[72,116,110],"tags":[],"class_list":["post-1237273","post","type-post","status-publish","format-standard","hentry","category-linux","category-lwn-net","category-unfiltered-rss"],"_links":{"self":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts\/1237273","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1237273"}],"version-history":[{"count":0,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts\/1237273\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1237273"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1237273"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1237273"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}