Weakness in Intel chips lets researchers steal encrypted SSH keystrokes

Peter Reutemann <[email protected]> Wed, 11 Sep 2019 11:49:31 +1200
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12K3iMR1_C_Z9OcYCkcdq188ekpp+auy=NCVOSR_SgdYcg@mail.gmail.com>
'In late 2011, Intel introduced a performance enhancement to its line
of server processors that allowed network cards and other peripherals
to connect directly to a CPU's last-level cache, rather than following
the standard (and significantly longer) path through the server's main
memory. By avoiding system memory, Intel's DDIO—short for Data-Direct
I/O—increased input/output bandwidth and reduced latency and power
consumption.

Now, researchers are warning that, in certain scenarios, attackers can
abuse DDIO to obtain keystrokes and possibly other types of sensitive
data that flow through the memory of vulnerable servers. The most
serious form of attack can take place in data centers and cloud
environments that have both DDIO and remote direct memory access
enabled to allow servers to exchange data. A server leased by a
malicious hacker could abuse the vulnerability to attack other
customers. To prove their point, the researchers devised an attack
that allows a server to steal keystrokes typed into the protected SSH
(or secure shell session) established between another server and an
application server.'

-- source: https://arstechnica.com/information-technology/2019/09/weakness-in-intel-chips-lets-researchers-steal-encrypted-ssh-keystrokes/

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list -- [email protected] | To unsubscribe send an email to [email protected]
Unsubscribe: %(web_page_url)slistinfo%(cgiext)s/%(_internal_name)s