Intel Let Google Cloud Hack Its New Secure Chips and Found 10 Bugs

Anil Rao, Intel’s vice president and general manager of systems architecture and engineering, says the opportunity for Intel and Google engineers to work as a team was particularly fruitful. The group had regular meetings, collaborated to track findings jointly, and developed a camaraderie that motivated them to bore even deeper into TDX.

Of the two vulnerabilities the researchers found that Rao called “critical,” one related to loose ends from a cryptographic integrity feature that had been dropped from the product. “It was a leftover thing that we didn’t catch, but the Google team caught it,” he says. The other major vulnerability uncovered by the project was in Intel’s Authenticated Code Modules, which are cryptographically signed chunks of code that are built to run in the processor at a particular time. The vulnerability involved a small window in which an attacker could have hijacked the mechanism to execute malicious code.

“For me, that was something which was surprising. I wasn’t expecting that we had such a vulnerability in our internal system,” Rao says. “But I was super happy that this team caught it. It’s not that these are easy vulnerabilities for someone to tap into, but the fact that it’s there is not a good thing. So at least once we fix it then we can sleep better at night.”

Rao and Porter also point out that the finding was significant because ACM is used in other Intel security products beyond TDX.

Additionally, as part of the collaboration, Google worked with Intel to open source the TDX firmware, low-level code that coordinates between hardware and software. This way, Google Cloud customers and Intel TDX users around the world will have more insight into the product.

“Confidential computing is an area where we are opening up and telling customers, ‘bring your most sensitive applications, bring your most sensitive data, and operate it on shared infrastructure in the cloud,’” Rao says. “So we want to make sure that we follow a rigorous process in ensuring that the key handlers of that sensitive data are rugged. Whether we like it or not, establishment of trust takes a long time, and you can break it very easily.”

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
מתקרבת אל ליגת העל: MSI מציגה את הספק העוצמתי ביותר שלה עד כה thumbnail

מתקרבת אל ליגת העל: MSI מציגה את הספק העוצמתי ביותר שלה עד כה

שנה וחצי אחרי שהענקית הטאיוואנית החליטה לנסות למצוא את מקומה גם בתחום ספקי הכח לגיימינג עם שלישיית דגמים צנועה יחסית – היא עוברת את רף ארבעת הספרות לראשונה עם דגם 1,000 וואט מחוזק פריחתו המחודשת של שוק ה-PC, ובפרט של תחום הגיימינג עתיר הביצועים, המחירים והיכולות, דוחף עוד ועוד יצרניות להרחיב ולגוון את ההיצע שלהן…
Read More
Here’s the full Google Chrome browser running on Fuchsia [Gallery] thumbnail

Here’s the full Google Chrome browser running on Fuchsia [Gallery]

Google’s homegrown Fuchsia operating system has taken another step closer to being broadly usable by gaining the full Google Chrome browser experience. For years now, we’ve been tracking the development of Fuchsia, from a bold UI on phones and the Pixelbook, to a more stripped back experience, to ultimately launching on the Nest Hub. In…
Read More
Sony expands its neck-band speaker line with the new SRS-NS7 thumbnail

Sony expands its neck-band speaker line with the new SRS-NS7

Reviews, News, CPU, GPU, Articles, Columns, Other "or" search relation.3D Printing, 5G, Accessory, AI, Alder Lake, AMD, Android, Apple, ARM, Audio, Business, Camera, Cannon Lake, Cezanne (Zen 3), Charts, Chinese Tech, Chromebook, Coffee Lake, Comet Lake, Console, Convertible / 2-in-1, Cryptocurrency, Cyberlaw, Deal, Desktop, E-Mobility, Exclusive, Fail, Foldable, Gadget, Galaxy Note, Galaxy S, Gamecheck, Gaming,…
Read More
Allianz study: Why electric car repairs are more expensive thumbnail

Allianz study: Why electric car repairs are more expensive

Cookies zustimmen Besuchen Sie Golem.de wie gewohnt mit Werbung und Tracking, indem Sie der Nutzung aller Cookies zustimmen. Details zum Tracking finden Sie im Privacy Center. Skript wurde nicht geladen. Informationen zur Problembehandlung finden Sie hier. Um der Nutzung von Golem.de mit Cookies zustimmen zu können, müssen Cookies in Ihrem Browser aktiviert sein. Weitere Informationen…
Read More
Samsung Galaxy S21 FE arrives in January, S22 series delayed? thumbnail

Samsung Galaxy S21 FE arrives in January, S22 series delayed?

06.10.2021 16:28 | Mobile Ranije glasine o otkazivanju objave Samsung Galaxy S21 FE 5G telefona su možda bile preuveličane. Dojavljivač Ice Universe tvrdi da će S21 FE biti objavljen uz S22 seriju krajem decembra ili početkom januara, dok Roland Quandt ističe da Samsung obavlja uobičajene pripreme pred objavu i da će S21 FE definitivno biti…
Read More
Index Of News