AMD PSP VULNERABILITY FOUND

If you thought AMD was safe from the ME hardware backdoor shit, think again. Their equivaent to ME (Platform "Secure" Processor) has been breached again. AMD BTFO

Other urls found in this thread:

seclists.org/fulldisclosure/2018/Jan/12
twitter.com/SFWRedditImages

Link:
seclists.org/fulldisclosure/2018/Jan/12

M A D
A
D

>09-28-17 - Vulnerability reported to AMD Security Team.
>12-07-17 - Fix is ready. Vendor works on a rollout to affected partners.
>01-03-18 - Public disclosure due to 90 day disclosure deadline.
So it's fixed already.

Intel also "fixed" their ME vulnerabilities
This doesn't change the fact that hardware backdoors are bad and should not exist. At least for Intel there's me_cleaner; AMD is too obscure to have an equivalent

Good thing i can just disable it then.

You can disable psp (access to it, which makes this kind of exploit useless) on some am4 boards already and, most likely, it's going to be standard feature on most of the new boards.

NOOO

>At least for Intel there's me_cleaner;
That doesn't work on a lot of Intel processors.

Holy shit the intel tryhards are doing a bad job today.

>AMD is too obscure to have an equivalent

what

DELET

...

Paid shills most of them. Intel paid millions for this army.

These researchers couldn't even test the found vulnerability on real hardware and had to resort to using an ARM virtual machine to demonstrate that the reference firmware implementation has this bug

intel is safe you amd fags can't divide intellians

>Without access to a real AMD hardware, we used an ARM emulator
I want this to be tested on a real hardware

lame damage control intel

So they found a problem in the TPM reference code that most vendors use, tested their exploit in an emulator, and now it's being called a PSP remote code execution vulnerability?

They never tried to test it on actual AMD hardware, and then they assumed (while not having any AMD hardware to verify with) that the PSP has no exploit mitigation technologies. And where are they getting the remote bit from? At best that's remote from the main cpu to the PSP cpu. I can't say I'm particularly impressed by this so far, especially seeing that a fix is ready and has been apparently rolling out for the past month. If anything I'm happy about this, not worried. Security working as it should: problem found, problem reported, problem fixed. Of course I'd be happier if all PSP code was open source of course, but maybe that can still happen some day.

NO WTF I JUST ORDERED RYZEN

>fixed since Dec 7th

Intel shills are getting desperate

see

>40 minutes ago
this is the third AMD PSP thread post-meltdown, and this is the third time you have been told that it's already fixed

I guess now that Intel is in some deep shit, what they're desperately trying to do is to find some kind of vulerability in AMD chips.

Fucking shills mane

*inhales* *exhales* *inhales* *exhales* *inhales*
SHUT UP
IT'S NOT TRUE

Fucking asus, I cant disable it

indeed you can't, even if that option would be available in your BIOS.
It just disables BIOS support. It doesn't disable PSP itself.

Oy Vey!!!, this post has been reported to my Uncle working in the FBI.

>this is an actual bios interface
what went wrong?

It's been patched already.

The goy is on to your tricks.

all those funds
might aswell pour them down the drain

AhMeD on suicide watch

The "remote" EK is part of NVRAM. In order to write to it, you'd need ring 0 access on the main CPU, or physical access.

He's working for that shekels instead of slacking. I respect that.

Where is my fucking money Intel?

BOTNET
O
T
N
E
T

Hope you intel trolls are getting overtime for all these FUD threads.

D A M A G E
C O N T R O L

>I love when things are highly unpratical

You want wrong user

*inhales* *exhales* *inhales* *exhales* *inhales* *exhales* *inhales* *exhales* *inhales* *exhales* *inhales* *exhales*

>he thinks it's actually turned off

Adorable

Do you have proof otherwise?

Xbone jailbreak when?

...

...

>everything clearly listed
>highly unpratical
u wot mate

>"Without access to a real AMD hardware, we used an ARM emulator"
why is this even allowed.

>bios getting more and more options every year
>with old interface you'd brake your up and down arrows before you configure anything
>practical
yes i agree that modern bios UI is cancer but it actually much easier and faster to use

juden

Delete this

haha
a a
h a
a h

PSP is only present in Ryzen Pro, you intel shill

Also, see this

>need physical access to the motherboard
kek

That modern BIOS also forces you to attach a high-end video card and 1080p monitor.

Not every board is a gamers board.