HardwareNews

AMD processors carry a serious vulnerability since the month of… SEPTEMBER!

Specter and Meltdown are still not fully resolved and a new vulnerability jumps, in this case only in AMD processors, specifically a serious security flaw in AMD Secure, which the company knows ... SINCE SEPTEMBER!

We are still at odds with Specter and Metldown, a serious vulnerability that mainly affects Intel processors, but also affects AMD and ARM processors and that has shaken the industry and that has also caused Intel to be seen under various demands. Well, there is no rest time, because now it is the AMD processors that are affected by a significant vulnerability and that is because the year is starting very uphill for the large processor manufacturers.

The vulnerability detected has to do with AMD Secure, a co-processor of the company's processors and which, luckily, is easily corrected, since with an update of the BIOS, UEFI or firmware, it is more than enough . Previously this co-processor, received the name of AMD Platform Security Processor or PSP. This is nothing more than a chip-on-chip security system and it looks a lot like the Intel Management Engine, which has been criticized on several occasions. The Intel and AMD systems are co-processors that are next to the cores, specifically this one from AMD together with the AMD64 x86, which has the mission of loading an independent operating system, which manages several operations related to security of the data that is processed.

Cfir Cohen has been the one who discovered the vulnerability and he is part of the security team of Google Cloud Security Team. This security expert says that he has detected the vulnerability in the Trusted Platform Module (TPM), which is within the AMD Secure. TPM's mission is to store critical system data, such as passwords, certificates and encryption keys, within a secure environment and outside the processor's own cores, something that makes it easily accessible.

This Google researcher reported the vulnerability to the company in SEPTEMBER, but the information has not been known until now. AMD told him in December that they had already created a patch and are finalizing its release. Time has passed and we are in January and the company has not launched it yet, so it has jumped to the public, to put pressure on the company. It seems that the two companies are sloppy and the safety of the users does not matter much to them, because they are not in a hurry to solve their shit. We have been eight days of the year and we are going to scandal, practically, every two days.

Show more

Robert Sole

Director of Contents and Writing of this same website, technician in renewable energy generation systems and low voltage electrical technician. I work in front of a PC, in my free time I am in front of a PC and when I leave the house I am glued to the screen of my smartphone. Every morning when I wake up I walk across the Stargate to make some coffee and start watching YouTube videos. I once saw a dragon ... or was it a Dragonite?

Related publications

5 comments

  1. It is a vulnerability that the patch has already corrected according to other means and is in the hands of the motherboard manufacturers and that it is the manufacturers who must send this patch in a BIOS update. The problem is not a problem at the moment as here it is wanted to think.

    1. 1. The patch has not been officially released, by AMD or anyone else.
      2. AMD knows since September.
      3. In December it should already be corrected and it is not.

  2. Let's compare headlines from this same blog.
    -A vulnerability in Intel processors has a fix, at the cost of losing performance
    -Intel before launching the Coffee Lake family, would already know that they were vulnerable to Specter and Meltdown
    versus
    -AMD processors carry a serious vulnerability since the month of ... SEPTEMBER!
    that has fix by software update, and without loss of performance.

    1. Extremist and sensationalist!!… in fact I stopped commenting a long time ago due to a “Serious security breach!” Every time I clicked on the box to write the comment, I was shown pop-up windows to pages with advertising and lots of nonsense!

Leave your comment

Your email address will not be published. Required fields are marked with *

Button back to top
CLOSE

Ad blocker detected

This site is funded through the use of advertising. We always make sure that the advertising is not too intrusive for the reader and we prioritize the reader's experience on the website. However, if you block the ads, part of our funding will be reduced.