In other words, if you're a consumer and you don't already have your computer pwned by malware, you're probably fine. You need an entry point in order to exploit this kind of stuff: physical access and/or local code execution.
-
-
Show this thread
-
I'm more concerned about AMD dragging their feet about the Spectre microcode update for my Threadripper than this stuff. These new flaws are more fun because they actually allow you to *take control* over PSP and defang it, *increasing* your security (a la me_cleaner for Intel).
Show this thread
End of conversation
New conversation -
-
-
Intel must be really happy about this. Oh wait ...
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
It looks like an attention seeking rehash of these issues reported in the beginning of January (when everybody was busy with Spectre/Meltdown): http://seclists.org/fulldisclosure/2018/Jan/12 …
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
this page says they all require admin privilege, so... (>'_')> https://www.anandtech.com/show/12525/security-researchers-publish-ryzen-flaws-gave-amd-24-hours-to-respond …
-
Exactly. This is just compromising higher-than admin privileges tiers. For consumers... That means you can use it to break DRM. And maybe BitLocker.
- Show replies
New conversation -
-
-
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
It's super weird that they did the PR well before they plan to disclose... seems risky, as though they didn't provide proofs of concept, their whitepaper might be enough to easily rediscover some of the issues. Page 3 is also weird - how does this make a self driving car unsafe?
-
The disclosure here seems totally dodgy, yes. These "teams" seem to be more concerned with naming and bragging rights and pushing a FUD narrative than actual security these days. OTOH rumor says AMD knew about some of these for years and never fixed them. ¯\_(ツ)_/¯
End of conversation
New conversation -
-
-
I wonder whether any of this applies to Jaguar for PS4 and Xbone fun.
-
Doubtful. Only the SP would be an issue, only Xbone has it and MS doesn't use AMD's firmware.
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
