Join Nostr
2025-02-03 20:27:12 UTC

cynicalsecurity :cm_2: on Nostr: From Bluesky it turns out that AMD microcode can be injected in certain cores ...

From Bluesky it turns out that AMD microcode can be injected in certain cores bypassing security checks because a weak hash function is used¹…

We have seen this before, of course, all the way back to the AMD K8 core in a very simple and short article by TESO.

I remember it well, I used it in my research and subsequent hacks, but it does leave me rather surprised that this is happening again.

On a separate note: I think having the possibility to modify microcode is wonderful and fun. It is an assembler to the processor, it lets you do some weird and wonderful things within the space of the microcode update store, of course (and its volatility: it has to be re-injected at boot, for a good reason, believe me :flan_XD:)

__
¹ https://github.com/google/security-research/security/advisories/GHSA-4xq7-4mgh-gp6w