Windows and Linux Get Options To Disable Intel TSX To Prevent Zombieload v2 Attacks

Peter Reutemann <[email protected]> Fri, 15 Nov 2019 08:31:47 +1300
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12JPZuXLDXWnRj_M6oYONiX=JzSaf13Dg9yjjDkFobU72Q@mail.gmail.com>
'Both Microsoft and the Linux kernel teams have added ways to disable
support for Intel Transactional Synchronization Extensions (TSX). From
a report:

TSX is the Intel technology that opens the company's CPUs to attacks
via the Zombieload v2 vulnerability. Zombieload v2 is the codename of
a vulnerability that allows malware or a malicious threat actor to
extract information processed inside a CPU, information to which they
normally shouldn't be able to access due to the security walls present
inside modern-day CPUs. This new vulnerability was disclosed earlier
this week. Intel said it would release microcode (CPU firmware)
updates -- available on the company's Support & Downloads center. But,
the reality of a real-world production environment is that performance
matters. Past microcode updates for other attacks, such as Meltdown,
Spectre, Foreshadow, Fallout, and Zombieload v1, have been known to
introduce performance hits of up to 40%. Seeing that all the CPU
attacks listed above are not only theoretical but also hard to pull
off, some companies don't see this performance hit as an option.'

-- source: https://tech.slashdot.org/story/19/11/14/1654247

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list -- [email protected] | To unsubscribe send an email to [email protected]
Unsubscribe: https://list.waikato.ac.nz/postorius/lists/wlug.list.waikato.ac.nz