You are not logged in.
...
New unfixable High Risk Security Issue on Intel CPU's. (Intel knows it since Mai 2019).
They can just try to make it harder to get inside a system, but not fix it.
https://securityboulevard.com/2020/03/n … ill-reign/
http://blog.ptsecurity.com/2020/03/inte … trust.html
https://cve.mitre.org/cgi-bin/cvename.c … -2019-0090
https://www.hardwareluxx.de/index.php/n … efahr.html
...
Last edited by Arkos (2020-03-07 19:13:07)
...
There also another Security Risk on all AMD CPU's back to Bulldozer named "Take away".
But it can be fixed by a Software Upgrade (UEFI).
https://mlq.me/download/takeaway.pdf
...
Last edited by Arkos (2020-03-07 19:19:19)
Some findings still suggest that once your network has been infiltrated, there are
far more easier and efficient ways to gather info rather than attacking the cpu.
Recommendations are as always, a multi-layered firewall.
...
Yes, but you know those security problems with Intel are pointed in many cases to the Cloud and Datacenters and big Servers.
From that moment it comes out that someones datas/secrets are stolen, the world would have a much bigger problem then with Corona Virus.
But with this last security issue from Intel it's even possible to read out bitlocked harddisks because they use this machinecode.
There are not only datacenters which datas must be safe.
I'm still convinced that many of those security holes were placed intentionally.
There's no easyer way to get datas then if you are the one who is controlling/selling the hardware.
They or intel just get the bill for this decision 10 years ago.
...
Last edited by Arkos (2020-03-08 02:33:46)
...
Hehe, this AMD Security Hole, Zombie-load light, "Take Away" ... the Team who discovered it is payed by Intel
Just let's wait what AMD is saying.
But i surley i think it's approved, otherwise it would have not been wisely to bring this out.
...
And there's another difference. Only parts can be read out with "Take away" as in Intel cases entire data sets are affected.
...
lí ḃaao
@gnyueh
· 18h
Replying to @lavados and 6 others
Thanks a lot for your work! I find it hard to read a paper which is irrelevant to my profession. Is this vulnerability as severe as Meltdown or Zombieload?
Daniel Gruss
@lavados
Certainly not. The attacks leak a few bit of meta-data. Meltdown and Zombieload leak tons of actual data.
9
10:12 AM - Mar 7, 2020
...
As far it seemse AMD will be able fix it by an UEFI Upgrade.
...
Last edited by Arkos (2020-03-08 03:12:17)
...
You know, ... the bitter part on this Intel Crypto Leak is that it can't be fixed.
This Cypto key is used for "Intel Management Engine" (ME), UEFI-Bios, DRM, the Trusted Platform Module (TPM) and the Software Guard Extensions (SGX), (Servers).
It was builded and sold to everybody as a security improvement. Now it seemse it's vice versa.
If this Crypto Key is read ot you have access to everything on this PC, DataCenter, Server etc. and this stays like this forever.
...
Btw. There are ways to deactivate as example Intel ME and others, but the point is, that this deactivation is done by a kill switch inside Bios but this kill switch is after the crypto key is allready loaded, (which happends before the bios is loading).
(Dell as example has this option and others also).
Like this it seemse it's really not fixable with a patch.
...
Last edited by Arkos (2020-03-08 04:03:58)
I got error messages about my TPM module (it say something like encryption still works, bitlocker), im on amd now, but the windows install originated from intel platform (win7) and then updated to win 10 on this amd platform.
Last edited by bud (2020-03-08 04:39:07)
...
I don't get it.
Is it AMD or Intel now?
But anyway, then i guess it could be a Driver problem.
...
Last edited by Arkos (2020-03-08 13:15:37)
...
Intel - New Security Issue - LVI (Load Value Injection)
LVI affects Intel Core-family processors from Skylake onwards with SGX support
https://www.bleepingcomputer.com/news/s … dware-fix/
https://www.hardwareluxx.de/index.php/n … soren.html
Not that bad like Intel Crypto Key Issue, (Take away), but still something what costs Performance to close it.
...
How LVI works
https://www.youtube.com/watch?v=goy8XRXFlh4
...
Performace Overhead
...
List of affected CPU's
https://software.intel.com/security-sof … -cpu-model
...
Closing LVI will cost exorbitant performance.
An anser from Uni Graz.
They say Intel has to make a complete new CPU. LVI cant be closed without huge performance loss.
„Diese Lücke ist sehr schwer zu schließen“, erklärt TU Graz-Forscher Daniel Gruss, der mit seinen Kollegen Michael Schwarz und Moritz Lipp einmal mehr im Zentrum der Entdeckung steht. „Es braucht dafür entweder einen ganz neuen Prozessor oder einen tiefen Eingriff in die Software. Die von Intel und uns parallel erarbeitete Software-Lösung wird massive Performance-Einbußen mit sich bringen.“ Das Team informierte Intel im bereits im April 2019 über die Entdeckung. „Wir haben uns auf diese lange Verschwiegenheit geeinigt, um Intel genügend Zeit für die notwendigen Fixes zu geben und die Computernutzenden keinem Risiko auszusetzen.“
Auch diesmal empfehlen die beteiligten Forschenden, alle Sicherheitsupdates der Hersteller einzuspielen und das eigene Computersystem abzusichern.
...
https://www.zdnet.com/article/intel-war … me-engine/
Security Issues at Intels Integrated GPU.
https://www.intel.com/content/www/us/en … 00315.html
Newest Intel Nucs have 2 heavy security issues and even the Intel Smart Sound is affected.
https://www.computerbase.de/2020-03/int … rafik-nuc/
...
If it goes on like this with Intel i would not be surprised about Messages in some years like:
"Your CPU is not compatible with Windows 12" or "Your CPU is not compatible with Google Chrome"
...
Last edited by Arkos (2020-03-12 01:12:24)
...
1. Windows 10 and event ID's are all 15?
2. Does this happen after wake up or in normal use.
3. Bios is up to date and drivers also? (From Gigabyte).
4. Which Gigabyte Board
...
Last edited by Arkos (2020-03-12 05:47:50)
...
Those security holes are gonna pandemic.
Microsoft Leaks Info on Wormable Windows SMBv3 CVE-2020-0796 Flaw
https://www.bleepingcomputer.com/news/s … 0796-flaw/
...
Last edited by Arkos (2020-03-12 05:55:03)
...
The Brutal Performance Impact From Mitigating The LVI Vulnerability.
It looks bad for Intel. Up to 75%+ performance loss. (SGX)
https://www.phoronix.com/scan.php?page= … perf&num=4
...
Btw. Privat users do not need SGX. Like this it affects only servers with activated SGX.
...
Last edited by Arkos (2020-03-13 14:48:03)
The first AMD Ryzen mobile "Renoir" APU are now available on Asus TUF FA506 laptop review (in English ) courtesy of Bob Of All Trades.
https://www.youtube.com/watch?v=Ee7cOygsUis
https://www.youtube.com/watch?v=60mAHC6VI5E
The only con/s for this gaming laptop was the 144Hz panel that used on this SKU, i.e.:
Last edited by Jesus Villamor (2020-03-30 12:20:42)
...
They allways make the same mistakes, also HP has horrible bad screens Displays.
Sadly some companies have the sole right to produce Laptops with 4800H.
I guess there is also none with just IGPU, which would be good enough. (At least for Workstations).
But anyway. This Mobile CPU is really nice.
...
...
A Ryzen 3900x in a Laptop
https://www.one.de/one-gaming-notebook- … 7af1-24564
Schenker made also a special serie with Ryzen 3000 (up to 3950x)
https://bestware.com/de/xmg-apex-15.html (Konfigurator, actual is 3600 CPU)
...
The Display of the XMG Apex is not bad for a gaming Laptop. 144Hz IPS 90% sRGB
I guess it's also the CLEVO NH57AF1 case... All those Laptops have the same display.
...
Last edited by Arkos (2020-03-31 14:40:07)
...
Mobile Gaming
Compare Intels supposed Monsters, 9980HK & RTX 2080 vs AMD 4900H & RTX 2060 @~half price
...
Last edited by Arkos (2020-04-03 00:23:26)
...
Intels answer with and deeper prices. (Juni 2020).
https://www.techpowerup.com/review/futu … #cometlake
...
Ryzen 4000 Desktop CPU's launch is at October 2020.
...
Last edited by Arkos (2020-04-28 13:27:38)
...
Ryzen 3300X (4Core + SMT).
(Small Budget for 1920x1080) ... wow!
https://www.tomshardware.com/reviews/am … u-review/3
In this video they used a 2080ti to get into CPU Limit.
https://youtu.be/i0ioHaQgl_Q?t=279
...
This little biest gives a view to the Ryzen 4000
...
Last edited by Arkos (2020-05-07 22:23:37)
...
...
Not to forget that at the 16. Juni the refreshs from Ryzen 3xxx and the B550 Boards will be launched and in Januar Ryzen 4xxx is coming.
...
Last edited by Arkos (2020-05-27 21:10:43)
so cool, wish i had that, i could play bf1 again ;-;
Last edited by Goldie (2020-05-27 21:08:52)
...
At 16. Juni new AMD's (Refresh) come out and the prices will go down a bit.
...
...
Hmm... there are rumors that Ryzen 4000 is coming in 5nm+
The reason, they say, due the blockade of Huawei they have free production capacities and AMD made an agreement with TSMC.
Another reason is, that 4700G disappeared in Bios, but others came in.
...
And Intel is still at 14nm+++++ etc
...
Last edited by Arkos (2020-05-28 22:12:15)
...
"Crosstalk" Security vulnerabilty on Intel CPU's
https://www.vusec.net/projects/crosstalk/
Affected CPU's
https://software.intel.com/security-sof … -cpu-model (ScrollDownList)
https://software.intel.com/security-sof … June9.xlsx (eXcel List)
...
They don't even think to close some of those holes, because it would cost too much performance.
...
Last edited by Arkos (2020-06-11 00:06:56)
...
Finally it's easier to adjust the CPU.
...
https://www.hardwareluxx.de/index.php/n … lting.html
https://wccftech.com/1usmus-unveils-clo … 3000-cpus/
...
The tested 3900x had 6.5% more performance while decreasing the power consumption by 9%.
...
Last edited by Arkos (2020-08-25 21:24:18)
...
In the first pictures, the Ryzen 5800x (8-16) Core at Standard Settings is faster then the 10-20 Core 10900k (@5.3Ghz + OC Memory)
(Ashes of Singularity and CPU-Z Bench-Screen).
In some weeks we are smarter.
...
Last edited by Arkos (2020-10-02 12:52:44)
.
one of two biggest amd events of the year coming up in three hours - 18:00 cet ..... the zen 3 launch (but their move to tsmc 5 nm in a year will be more interesting ) .... i actually favor intel and dislike amd
https://www.youtube.com/watch?v=iuiO6rq … =emb_title
im a bit of a tech / hardware enthusiast and follow certain segments of the industries
of the more consumer-oriented, like
amd
nvidia
apple
samsung
intel
and related
those are ones where i often watch their live launch events