Moneycontrol PRO
Loans
Loans
HomeNewsTechnologyHertzbleed: The security vulnerability that affects all modern Intel and AMD CPUs

Hertzbleed: The security vulnerability that affects all modern Intel and AMD CPUs

The vulnerability lets attackers steal encryption keys using a side channel attack

June 16, 2022 / 12:39 IST
Representative Image

A new security vulnerability discovered by researchers from University of Texas, University of Illinois Urbana-Champaign and the University of Washington in the US, lets attackers steal cryptographic keys from all modern Intel and AMD CPUs.

Called Hertzbleed, the vulnerability has been observed in the dynamic voltage and frequency scaling modules on the chip, which are used to regulate clock speeds and conserve power to reduce heat produced by the chip.

Using the Hertzbleed attack, the attacker can observe the power signature of any cryptographic key. Normally, the power signature of keys tend to be dynamic as the CPU adjusts clock frequencies according to the workload.

However, Hertzbleed allows the attacker to convert that power signature into timing data, which allows them to locate and steal crypto keys. This vulnerability affects all Intel processors, and AMD's Zen 2 and Zen 3 processors. What's worse is that the attack can be done remotely, requiring no physical access of the CPUs.

AMD and Intel have both issued security advisories for the issue, and AMD stated that, "As the vulnerability impacts a cryptographic algorithm having power analysis-based side channel leakages, developers can apply countermeasures on the software code of the algorithm. Either masking, hiding, or key-rotation may be used to mitigate the attack."

Intel also took a similar stance, saying that they do not believe that this vulnerability can be exploited and the attack was not, "practical outside of a lab environment."

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

Moneycontrol News
first published: Jun 16, 2022 12:39 pm

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347