GLOBAL RESEARCH SYNDICATE
No Result
View All Result
  • Login
  • Latest News
  • Consumer Research
  • Survey Research
  • Marketing Research
  • Industry Research
  • Data Collection
  • More
    • Data Analysis
    • Market Insights
  • Latest News
  • Consumer Research
  • Survey Research
  • Marketing Research
  • Industry Research
  • Data Collection
  • More
    • Data Analysis
    • Market Insights
No Result
View All Result
globalresearchsyndicate
No Result
View All Result
Home Data Collection

Intel CPU Security Alert For Millions Of Users As ‘Unfixable’ Crypto Flaw Revealed

globalresearchsyndicate by globalresearchsyndicate
March 5, 2020
in Data Collection
0
Intel CPU Security Alert For Millions Of Users As ‘Unfixable’ Crypto Flaw Revealed
0
SHARES
3
VIEWS
Share on FacebookShare on Twitter

The Intel logo, white against a purple background

Researchers report an “unfixable” crypto flaw affects millions of systems with Intel chipsets.


Getty Images

If your computer isn’t running an up to date Intel 10th generation CPU, then I’ve got some bad news; an “unfixable” crypto vulnerability with impossible to detect exploits has been confirmed. Researchers have uncovered an Intel CPU read-only memory (ROM) vulnerability with the potential for attackers to compromise encryption keys and steal data. Mark Ermolov, the report author, said that it’s “impossible to fix firmware errors that are hard-coded in the Mask ROM of microprocessors and chipsets.” This is rather concerning when you take into account that a successful exploit would be at the hardware level and so, according to Ermolov, “it destroys the chain of trust for the platform as a whole.”

What is CVE-2019-0090, and why does it matter?

There have been quite a few crypto-related security scares of late, including the NSA-reported ‘Curveball‘ threat to Windows 10 users. How does CVE-2019-0090 stack up in terms of criticality?

The CVE-2019-0090 vulnerability concerns the Converged Security and Management Engine (CSME) within most Intel CPUs released over the last five years, those 10th generation iterations being the exception. It’s a big deal because CSME is, in effect, the computer inside the Intel inside your computer. It provides the low-level cryptographic verifications when the motherboard boots, among other things. It’s the first thing that runs when you hit the power switch and the root of trust for everything that follows.

If CVE-2019-0090 sounds familiar, then firstly, you are a security geek of the first order. More importantly, it was disclosed back in May 2019 when Intel released a security update to fix it. That fix, it turns out, was but a partial one that dealt with just one potential attack vector. Although full details are being withheld at the moment, Ermolov did state in the Positive Technologies report that “there might be many ways to exploit this vulnerability in ROM,” not all requiring physical access, some just local malware-related access.

It’s not all bad news, out here in the real world

There is some good news among the bad, though, and we must keep the attack potential in real-world perspective: exploiting this vulnerability to any valuable end is far from easy. While the Enhanced Privacy ID (EPID) procedure at the heart of the root of trust mentioned before is vulnerable to a reading of the Chipset Key which could then allow an attacker to bypass authenticity checks in CSME firmware module code, that key itself is encrypted within the One-Time Programmable (OTP) memory. “To fully compromise EPID,” Ermolov said, “hackers would need to extract the hardware key used to encrypt the Chipset Key, which resides in Secure Key Storage (SKS).” This is not trivial by any means, and there is no evidence that anyone has figured out how to obtain the hard-coded hardware key component directly. 

“We believe that extracting this key is only a matter of time,” Ermolov warned, adding that when this does happen, then “hardware IDs will be forged, digital content will be extracted, and data from encrypted hard disks will be decrypted.”

Eoin Keary, CEO and co-founder of edgescan, says that this is “a fundamental flaw which cannot be easily fixed with a simple patch, and it’s also extremely widespread. It cannot be fixed in the ROM of existing hardware.” He tempers this by agreeing that “a successful exploit would need to be advanced in nature and well-engineered by advanced threat actors.”

Intel offers mitigation guidance

An Intel spokesperson responded to my request for comment on the matter with the following statement by email: “Intel was notified of a vulnerability potentially affecting the Intel Converged Security Management Engine in which an unauthorized user with specialized hardware and physical access may be able to execute arbitrary code within the Intel CSME subsystem on certain Intel products. Intel released mitigations and recommends keeping systems up-to-date. Additional guidance specific to CVE-2019-0090 can be found here.”

Positive Technologies advises that since it’s impossible to totally fix the vulnerability without replacing the hardware, users should disable Intel CSME based encryption of data storage devices or consider migration to tenth-generation or later Intel CPUs.

Marco Essomba, founder of iCyber-Security, says that “since this vulnerability requires some sort of local or physical access to be exploited, it’s strongly recommended organizations review their physical access control security.” Implementing a defense in layer approach where security is enforced at both physical and software levels is also recommended by Essomba.

Related Posts

How Machine Learning has impacted Consumer Behaviour and Analysis
Consumer Research

How Machine Learning has impacted Consumer Behaviour and Analysis

January 4, 2024
Market Research The Ultimate Weapon for Business Success
Consumer Research

Market Research: The Ultimate Weapon for Business Success

June 22, 2023
Unveiling the Hidden Power of Market Research A Game Changer
Consumer Research

Unveiling the Hidden Power of Market Research: A Game Changer

June 2, 2023
7 Secrets of Market Research Gurus That Will Blow Your Mind
Consumer Research

7 Secrets of Market Research Gurus That Will Blow Your Mind

May 8, 2023
The Shocking Truth About Market Research Revealed!
Consumer Research

The Shocking Truth About Market Research: Revealed!

April 25, 2023
market research, primary research, secondary research, market research trends, market research news,
Consumer Research

Quantitative vs. Qualitative Research. How to choose the Right Research Method for Your Business Needs

March 14, 2023
Next Post
Market – Recent Industry Developments and Growth Strategies Adopted by Top Players Worldwide 2020-2024 – Bandera County Courier

Market 2020 Outlook by Market Entry Strategies, Countermeasures of Economic Impact & Forecast by 2024 with Top Players – Honda Motor Company, Visa, Mastercard, ZF Friedrichshafen, Toyota Motor Corporation, Audi AG, BMW, Daimler AG – Bandera County Courier

Categories

  • Consumer Research
  • Data Analysis
  • Data Collection
  • Industry Research
  • Latest News
  • Market Insights
  • Marketing Research
  • Survey Research
  • Uncategorized

Recent Posts

  • Ipsos Revolutionizes the Global Market Research Landscape
  • How Machine Learning has impacted Consumer Behaviour and Analysis
  • Market Research: The Ultimate Weapon for Business Success
  • Privacy Policy
  • Terms of Use
  • Antispam
  • DMCA

Copyright © 2024 Globalresearchsyndicate.com

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT
No Result
View All Result
  • Latest News
  • Consumer Research
  • Survey Research
  • Marketing Research
  • Industry Research
  • Data Collection
  • More
    • Data Analysis
    • Market Insights

Copyright © 2024 Globalresearchsyndicate.com