Researchers Exploit Another Intel Hyper-Threading Flaw

Contributor

Lucian Armasu is a Contributing Writer for Tom's Hardware US. He covers software news and the issues surrounding privacy and security.

  • remus.mihai26
    Laughts in i7 9700k
    Reply
  • stdragon
    It's hypothetical. They haven't cracked an encrypted session; and I doubt they'll ever be able too. That said, again, Theo de Raadt already pointed out that SMT was susceptible to side-channel exploits.

    https://marc.info/?l=openbsd-tech&m=153504937925732&w=2

    August 23, 2018

    "Two recently disclosed hardware bugs affected Intel cpus:

    - TLBleed

    - T1TF (the name "Foreshadow" refers to 1 of 3 aspects of this
    bug, more aspects are surely on the way)

    Solving these bugs requires new cpu microcode, a coding workaround,
    *AND* the disabling of SMT / Hyperthreading.

    SMT is fundamentally broken because it shares resources between the two
    cpu instances and those shared resources lack security differentiators.
    Some of these side channel attacks aren't trivial, but we can expect
    most of them to eventually work and leak kernel or cross-VM memory in
    common usage circumstances, even such as javascript directly in a
    browser.

    There will be more hardware bugs and artifacts disclosed. Due to the
    way SMT interacts with speculative execution on Intel cpus, I expect SMT
    to exacerbate most of the future problems.

    A few months back, I urged people to disable hyperthreading on all
    Intel cpus. I need to repeat that:

    DISABLE HYPERTHREADING ON ALL YOUR INTEL MACHINES IN THE BIOS."
    Reply
  • TechyInAZ
    So this is why the 9700K doesn't have hyperthreading. hahahha.
    Reply
  • racksmith101
    This is why most of the new Intel 9gen CPU's don't have it.
    Reply
  • Geef
    Darn those hackers, they are gonna steal my pr0nhub account password with this flaw
    Reply
  • jpe1701
    Yeah I'm sure that's why there's no hyperthreading on the 9700k. That's a good one. That Intel, they're so good to their customers.
    Reply
  • SkyBill40
    While I know AMD isn't out of the woods here seeing that they use SMT, since nothing was yet stated as affecting their CPUs, this can't be anything but a blessing for them and another bad beat for Intel. If they don't develop a new architecture and soon, OS patches and BIOS updates are going to become as frequent as changing one's socks.
    Reply
  • jimmysmitty
    21453323 said:
    It's hypothetical. They haven't cracked an encrypted session; and I doubt they'll ever be able too. That said, again, Theo de Raadt already pointed out that SMT was susceptible to side-channel exploits.

    https://marc.info/?l=openbsd-tech&m=153504937925732&w=2

    August 23, 2018

    "Two recently disclosed hardware bugs affected Intel cpus:

    - TLBleed

    - T1TF (the name "Foreshadow" refers to 1 of 3 aspects of this
    bug, more aspects are surely on the way)

    Solving these bugs requires new cpu microcode, a coding workaround,
    *AND* the disabling of SMT / Hyperthreading.

    SMT is fundamentally broken because it shares resources between the two
    cpu instances and those shared resources lack security differentiators.
    Some of these side channel attacks aren't trivial, but we can expect
    most of them to eventually work and leak kernel or cross-VM memory in
    common usage circumstances, even such as javascript directly in a
    browser.

    There will be more hardware bugs and artifacts disclosed. Due to the
    way SMT interacts with speculative execution on Intel cpus, I expect SMT
    to exacerbate most of the future problems.

    A few months back, I urged people to disable hyperthreading on all
    Intel cpus. I need to repeat that:

    DISABLE HYPERTHREADING ON ALL YOUR INTEL MACHINES IN THE BIOS."

    I just wonder is this is Intel SMT specific or all SMT. And does it affect older implementations of SMT considering that SMT has changed a lot since it first debut.

    21453496 said:
    While I know AMD isn't out of the woods here seeing that they use SMT, since nothing was yet stated as affecting their CPUs, this can't be anything but a blessing for them and another bad beat for Intel. If they don't develop a new architecture and soon, OS patches and BIOS updates are going to become as frequent as changing one's socks.

    Thats part of my question too though. Are these same researchers testing AMD also or just Intel? While it is different AMDs current implementation of SMT is the similar to Intels so it could be vulnerable to the same attacks or even ones Intel may not be.

    The uASrch is not really part of it though. SMT is a feature Intel could easily bake out of the Core arch, remember when Intel went dual core they dropped HT from the Netburst arch.
    Reply
  • SkyBill40
    21453804 said:
    21453496 said:
    While I know AMD isn't out of the woods here seeing that they use SMT, since nothing was yet stated as affecting their CPUs, this can't be anything but a blessing for them and another bad beat for Intel. If they don't develop a new architecture and soon, OS patches and BIOS updates are going to become as frequent as changing one's socks.

    Thats part of my question too though. Are these same researchers testing AMD also or just Intel? While it is different AMDs current implementation of SMT is the similar to Intels so it could be vulnerable to the same attacks or even ones Intel may not be.

    The uASrch is not really part of it though. SMT is a feature Intel could easily bake out of the Core arch, remember when Intel went dual core they dropped HT from the Netburst arch.

    One would certainly hope so for the sake of thoroughness and accuracy. I do know that the main nasties in Spectre, Meltdown, and Heartbleed really didn't play rough on AMD due to the way their architecture is designed; however, that's not to say that they escaped unscathed as we did see OS related patches come about and largely just in case. Even as overblown as the whole "Ryzenfall" mess was by that halfwit group from CT Labs, AMD saw fit to investigate it and patch.

    If Intel wants to bake out the SMT as you mentioned, they'll have to do that as another 14nm revision unless they make the change on whatever they release as a completely new build and we all know how they're struggling mightily with progress towards 10nm.

    Reply
  • emeralds1000000
    Intel itself may have started to listen to this advice, as the company’s Core i7-9700K will be the first Core i7 in the company’s history to ship without HT.

    yea Right , how about the tons of Xeons CPU ? in which security is far more important than gaming PCs ? what advice and what "listened" and what i7 9700K ???

    this is a Serious issue that concern Servers and Huge companies alot. and not the gamers.

    Reply