• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

13 Major Vulnerabilities Discovered in AMD Zen Architecture, Including Backdoors

Joined
Mar 10, 2014
Messages
1,793 (0.48/day)
The "researchers" jumped the gun. AMD hasn't even had time yet to reproduce them for verification purposes.

When Specter and Meltdown went public, it was huge news because despite having six months to work on it, they weren't even close to fixing it. Even if one of these 13 ends up being legit, it most likely could have been quietly fixed without any fanfare. In this case, everything the "researchers" did was about maximizing fanfare. That should concern everyone. I hope this doesn't become the new norm but it could.

Well I agree it's very very poorly executed if that indeed is genuine security firm. But looking on employees backgrounds, I have hard time to discredit their expertise in security.
 
Joined
May 30, 2015
Messages
1,873 (0.58/day)
Location
Seattle, WA
The double standard is real. Let's jump the gun and defame the researchers because this is AMD and not Intel. Hell, the AMD defense force has yet to provide actual evidence to discredit each of those findings but somehow someway found a way to link this to Intel. This AMD circlejerk culture, even though it's a vocal minority, has to stop.

The accused does not generally carry the burden of proof.

When Meltdown and Spectre went public there was sample code, a real-time demonstration, step-by-step info on each avenue of attack. Multiple tech giants had it in-hand for months working on a fix before it went live. This report has none of those things and holds little credence in it's vague descriptions, lack of review, and immediate public exposure.
 
Joined
Nov 30, 2015
Messages
712 (0.23/day)
Location
Croatia
Processor Ryzen 5 3600 PRO
Motherboard AsRock B450 Pro4
Cooling Arctic Freezer 34 /w Noctua NF-P12
Memory Silicon Power XPower Zenith 2x8GB @1600 MHz
Video Card(s) Gigabyte RTX 2070 Super Gaming OC 8GB
Storage Crucial P5 Plus 1TB / Crucial MX 500 1TB
Display(s) Dell P2419H
Case Fractal Design Pop Air /w 3x Arctic P12 PWM
Audio Device(s) Creative Sound Blaster Z + Edifier R1000T4
Power Supply Super Flower Leadex III 650W
Mouse Microsoft Intelimouse Pro
Keyboard IBM KB-8926
Software Windows 10 Pro 64-bit
Benchmark Scores Turns on on the first try! Usually.
If this didn't involve such allegations it would be really really funny, almost like an article from The Onion, with the green screened scenes and everything. But this is just lame, a low blow to either smear the company/the new product or for a financial gain through stock trading.

And ffs, the sites name is AMDFlaws.

Also, whether these vulnerabilities are real or not, the tech sites (some at least) have lost a lot of respect in my eyes, posting such news without an in depth research, gotta get them clicks huh.
 
Joined
Jun 1, 2007
Messages
150 (0.02/day)
Location
new jersey usa
If this didn't involve such allegations it would be really really funny, almost like an article from The Onion, with the green screened scenes and everything. But this is just lame, a low blow to either smear the company/the new product or for a financial gain through stock trading.

And ffs, the sites name is AMDFlaws.

Also, whether these vulnerabilities are real or not, the tech sites (some at least) have lost a lot of respect in my eyes, posting such news without an in depth research, gotta get them clicks huh.


I feel like that too about any type of unconfirmed rumors at least when you have people or money involved.
to be fair most real sites show dought because of the way it was brought to the table
 
Joined
Aug 20, 2007
Messages
20,787 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
I hope it's not going to upset w1zzard, but from what limited research I can confirm as a "non-press" member at this time, I'm going to have to side with the users here:

If this is even true, it stinks of an Intel PR stunt.

It's possibly not even true?

What is it doing in the news feed?

gotta get them clicks huh.

I think everyone is entitled to an honest mistake and/or "jumping the gun" on occasion. But if this turns out to be false, TPU sure had better follow up with a retraction, I would think.
 
Joined
Nov 30, 2015
Messages
712 (0.23/day)
Location
Croatia
Processor Ryzen 5 3600 PRO
Motherboard AsRock B450 Pro4
Cooling Arctic Freezer 34 /w Noctua NF-P12
Memory Silicon Power XPower Zenith 2x8GB @1600 MHz
Video Card(s) Gigabyte RTX 2070 Super Gaming OC 8GB
Storage Crucial P5 Plus 1TB / Crucial MX 500 1TB
Display(s) Dell P2419H
Case Fractal Design Pop Air /w 3x Arctic P12 PWM
Audio Device(s) Creative Sound Blaster Z + Edifier R1000T4
Power Supply Super Flower Leadex III 650W
Mouse Microsoft Intelimouse Pro
Keyboard IBM KB-8926
Software Windows 10 Pro 64-bit
Benchmark Scores Turns on on the first try! Usually.
I feel like that too about any type of unconfirmed rumors at least when you have people or money involved.
Yea, I don't know if it's just me but I see a lot of these kind of "news" lately.
I hope it's not going to upset w1zzard, but from what limited research I can confirm as a "non-press" member at this time, I'm going to have to side with the users here:

If this is even true, it stinks of an Intel PR stunt.

It's possibly not even true?

What is it doing in the news feed?



I think everyone is entitled to an honest mistake and/or "jumping the gun" on occasion. But if this turns out to be false, TPU sure had better follow up with a retraction, I would think.
Of course, I am also partly at fault here, because until all of this clears up we don't really know who is right or who is wrong.
 
Joined
Jun 1, 2007
Messages
150 (0.02/day)
Location
new jersey usa
I hope it's not going to upset w1zzard, but from what limited research I can confirm as a "non-press" member at this time, I'm going to have to side with the users here:

If this is even true, it stinks of an Intel PR stunt.

It's possibly not even true?

What is it doing in the news feed?



I think everyone is entitled to an honest mistake and/or "jumping the gun" on occasion. But if this turns out to be false, TPU sure had better follow up with a retraction, I would think.

yeah but btarunr is such a news hound and has been for years
you guys haveta know he is crazy for news I think he is like, screw it let god sort it out.
there was no facebook or twitter or even good goggle we had him and wizz
 
Joined
May 6, 2012
Messages
184 (0.04/day)
Location
Estonia
System Name Steamy
Processor Ryzen 7 2700X
Motherboard Asrock AB350M-Pro4
Cooling Wraith Prism
Memory 2x8GB HX429C15PB3AK2/16
Video Card(s) R9 290X WC
Storage 960Evo 500GB nvme
Case Fractal Design Define Mini C
Power Supply Seasonic SS-660XP2
Software Windows 10 Pro
Benchmark Scores http://hwbot.org/user/kinski/ http://valid.x86.fr/qfxqhj https://goo.gl/uWkw7n
I call a big juicy BS.

https://amdflaws.com/disclaimer.html

The report and all statements contained herein are opinions of CTS and are not statements of fact. To the best of our ability and belief, all information contained herein is accurate and reliable, and has been obtained from public sources we believe to be accurate and reliable.

Although we have a good faith belief in our analysis and believe it to be objective and unbiased, you are advised that we may have, either directly or indirectly,
an economic interest in the performance of the securities of the companies whose products are the subject of our reports.
 
Joined
Jul 9, 2015
Messages
3,413 (1.06/day)
System Name M3401 notebook
Processor 5600H
Motherboard NA
Memory 16GB
Video Card(s) 3050
Storage 500GB SSD
Display(s) 14" OLED screen of the laptop
Software Windows 10
Benchmark Scores 3050 scores good 15-20% lower than average, despite ASUS's claims that it has uber cooling.
Heck, and one would think people don't swallow bait like this on a techie site.

"If you infect BIOS you can do baaaaad things"
"If you have admin rights then you can start a program and do baaaad things"
"if you have admin rights you can start a program and read stuff from memory!!!"


Are you FREAKING kidding me?
 
Joined
Apr 26, 2008
Messages
231 (0.04/day)
System Name 3950X Workstation
Processor AMD Ryzen 9 3950X
Motherboard ASUS Crosshair VIII Impact
Cooling Cryorig C1 with Noctua NF-A12x15
Memory G.Skill F4-3600C16D-32GTZNC
Video Card(s) ASUS GTX 1650 LP OC
Storage 2 x Corsair MP510 1920GB M.2 SSD
Case Realan E-i7
Power Supply G-Unique 400W
Software Win 10 Pro
Benchmark Scores https://smallformfactor.net/forum/threads/the-saga-of-the-little-gem-continues.12877/
Joined
Jan 31, 2005
Messages
2,053 (0.29/day)
Location
Denmark
System Name Commercial towing vehicle "Nostromo"
Processor 5800X3D
Motherboard X570 Unify
Cooling EK-AIO 360
Memory 32 GB Fury 3666 MHz
Video Card(s) 4070 Ti Eagle
Storage SN850 NVMe 1TB + Renegade NVMe 2TB + 870 EVO 4TB
Display(s) 25" Legion Y25g-30
Case Lian Li LanCool 216 v2
Audio Device(s) B & W PX7 S2e
Power Supply HX1500i
Mouse Harpe Ace Aim Lab Edition
Keyboard Scope II 96 Wireless
Software Windows 11 23H2
Joined
Oct 19, 2007
Messages
8,197 (1.36/day)
Processor Intel i9 9900K @5GHz w/ Corsair H150i Pro CPU AiO w/Corsair HD120 RBG fan
Motherboard Asus Z390 Maximus XI Code
Cooling 6x120mm Corsair HD120 RBG fans
Memory Corsair Vengeance RBG 2x8GB 3600MHz
Video Card(s) Asus RTX 3080Ti STRIX OC
Storage Samsung 970 EVO Plus 500GB , 970 EVO 1TB, Samsung 850 EVO 1TB SSD, 10TB Synology DS1621+ RAID5
Display(s) Corsair Xeneon 32" 32UHD144 4K
Case Corsair 570x RBG Tempered Glass
Audio Device(s) Onboard / Corsair Virtuoso XT Wireless RGB
Power Supply Corsair HX850w Platinum Series
Mouse Logitech G604s
Keyboard Corsair K70 Rapidfire
Software Windows 11 x64 Professional
Benchmark Scores Firestrike - 23520 Heaven - 3670
Joined
Feb 17, 2010
Messages
1,488 (0.29/day)
Location
Azalea City
System Name Main
Processor Ryzen 5950x
Motherboard B550 PG Velocita
Cooling Water
Memory Ballistix
Video Card(s) RX 6900XT
Storage T-FORCE CARDEA A440 PRO
Display(s) Samsung UE590
Case QUBE 500
Audio Device(s) Logitech Z623
Power Supply LEADEX V 1KW
Mouse Cooler Master MM710
Keyboard Huntsman Elite
Software 11 Pro
Benchmark Scores https://hwbot.org/user/damric/
This smells political...and reeks of a Trump-Netanyahu-Intel circle jerk.

First Trump killed the Broadcom merger with Qualcom...who does that benefit? Intel. Who makes Intel chips? Israelis.

Now this weird unknown security company sounds like something concocted overnight by the same fake news exporters that we saw during the 2016 U.S. presidential campaign. Sure, there might be some half-truths, but bottom line is that ordinary good security practices protect you from most of this.
 
Joined
Dec 29, 2010
Messages
3,455 (0.71/day)
Processor AMD 5900x
Motherboard Asus x570 Strix-E
Cooling Hardware Labs
Memory G.Skill 4000c17 2x16gb
Video Card(s) RTX 3090
Storage Sabrent
Display(s) Samsung G9
Case Phanteks 719
Audio Device(s) Fiio K5 Pro
Power Supply EVGA 1000 P2
Mouse Logitech G600
Keyboard Corsair K95
This smells political...and reeks of a Trump-Netanyahu-Intel circle jerk.

First Trump killed the Broadcom merger with Qualcom...who does that benefit? Intel. Who makes Intel chips? Israelis.

Now this weird unknown security company sounds like something concocted overnight by the same fake news exporters that we saw during the 2016 U.S. presidential campaign. Sure, there might be some half-truths, but bottom line is that ordinary good security practices protect you from most of this.

It's a a short seller trying to screw AMD stock price.

https://www.iol.co.za/business-repo...-and-why-do-their-accusations-matter-13010688

For example:

"Astute social-media users have noted that Viceroy Research, a financial-analysis group that reportedly engages in short selling of various companies' securities, appears to have coordinated the release of a report provocatively titled "The Obituary" alongside the CTS Labs whitepaper."

https://techreport.com/news/33368/s...of-ryzen-epyc-and-amd-chipset-vulnerabilities
 
Low quality post by xkm1948
Joined
Mar 18, 2008
Messages
5,717 (0.97/day)
System Name Virtual Reality / Bioinformatics
Processor Undead CPU
Motherboard Undead TUF X99
Cooling Noctua NH-D15
Memory GSkill 128GB DDR4-3000
Video Card(s) EVGA RTX 3090 FTW3 Ultra
Storage Samsung 960 Pro 1TB + 860 EVO 2TB + WD Black 5TB
Display(s) 32'' 4K Dell
Case Fractal Design R5
Audio Device(s) BOSE 2.0
Power Supply Seasonic 850watt
Mouse Logitech Master MX
Keyboard Corsair K70 Cherry MX Blue
VR HMD HTC Vive + Oculus Quest 2
Software Windows 10 P
This smells political...and reeks of a Trump-Netanyahu-Intel circle jerk.

First Trump killed the Broadcom merger with Qualcom...who does that benefit? Intel. Who makes Intel chips? Israelis.

Now this weird unknown security company sounds like something concocted overnight by the same fake news exporters that we saw during the 2016 U.S. presidential campaign. Sure, there might be some half-truths, but bottom line is that ordinary good security practices protect you from most of this.


Come on, even the Russian collusion story found a juicy nothing buger. How the hell can you link this to Trump? Government level smearing operation is way better executed. This one on the other side is very poorly executed
 
Joined
Jul 5, 2013
Messages
25,559 (6.48/day)
And your insinuation is?
Seems he was implying the use of coincidental irony.

After reading the documentation provided by a few different sources, my $0.02 is this;
1; This not so secret "Secret Processor" nonsense needs to go or be updated to be user configured/disabled as it is a severe potential security risk,
2; There is validity to some of the scare of this paper, but not all.
3; Many aspects of these claims require physical access to the hardware and/or serious alteration to the base software(bios/efi), neither of which is practical for remote attack.

This smells political...and reeks of a Trump-Netanyahu-Intel circle jerk.
As unlikely as that is, let's keep the politics out of this and focus on factual information. Conspiracy theory's are not very helpful.
 
Joined
Dec 30, 2010
Messages
2,098 (0.43/day)
Great testing, esp. when:

1: system needs adjusted bios
2: user needs to be in administrator mode

It's not as bad as it is for Intel with Spectre and Meltdown.

I could think of an instance, https://www.spamfighter.com/News-21...ussias-Hacking-Group-Fancy-Bear-Suspected.htm

where computers that where ordered at large scale, any vendor is able to inject some sort of adjusted bios into the hardware, and send out to in this case, a goverment which opens door on spying.

But furthermore; you shoud'nt worry much about the flaws in AMD hardware. This is a merely PR message, 24 hours responsetime is very very unreal.
 
Joined
May 19, 2009
Messages
1,823 (0.33/day)
Location
Latvia
System Name Personal \\ Work - HP EliteBook 840 G6
Processor 7700X \\ i7-8565U
Motherboard Asrock X670E PG Lightning
Cooling Noctua DH-15
Memory G.SKILL Trident Z5 RGB Black 32GB 6000MHz CL36 \\ 16GB DDR4-2400
Video Card(s) ASUS RoG Strix 1070 Ti \\ Intel UHD Graphics 620
Storage 2x KC3000 2TB, Samsung 970 EVO 512GB \\ OEM 256GB NVMe SSD
Display(s) BenQ XL2411Z \\ FullHD + 2x HP Z24i external screens via docking station
Case Fractal Design Define Arc Midi R2 with window
Audio Device(s) Realtek ALC1150 with Logitech Z533
Power Supply Corsair AX860i
Mouse Logitech G502
Keyboard Corsair K55 RGB PRO
Software Windows 11 \\ Windows 10
Everything that can be said, is already said by others. Let's see what AMD will give in full answer.
 
Joined
Jul 5, 2013
Messages
25,559 (6.48/day)
It's not as bad as it is for Intel with Spectre and Meltdown.
It's too early to claim that. The devil is in the details and those are still being sorted out. Like with Meltdown, the initial reaction is an over-reaction.
But furthermore; you shouldn't worry much about the flaws in AMD hardware. This is a merely PR message, 24 hours response time is very very unreal.
Again, it's too early to claim such.
 
Joined
Dec 29, 2010
Messages
3,455 (0.71/day)
Processor AMD 5900x
Motherboard Asus x570 Strix-E
Cooling Hardware Labs
Memory G.Skill 4000c17 2x16gb
Video Card(s) RTX 3090
Storage Sabrent
Display(s) Samsung G9
Case Phanteks 719
Audio Device(s) Fiio K5 Pro
Power Supply EVGA 1000 P2
Mouse Logitech G600
Keyboard Corsair K95
It's too early to claim that. The devil is in the details and those are still being sorted out. Like with Meltdown, the initial reaction is an over-reaction.

Again, it's too early to claim such.

Seriously, drop the official business act. This is a ruse.
 
Top