• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

8 Months on, AMD's catastrophic RYZEN hardware PSP vulnerabilities left unpatched.

Status
Not open for further replies.

rugabunda

New Member
Joined
May 22, 2018
Messages
24 (0.01/day)
AMD deleted the following from Reddit; immediately after, Reddit blocked my ability to login. Its called the Talpiot Program. "Tribal chutzpa."

Its been 8 months since Mark Papermaster, Senior Vice President and Chief Technology Officer at AMD has acknowledged hardware level RYZENFALL, FALLOUT, CHIMERA, MASTERKE vulnerabilities, originally exploited by Israel's CTS. AMD's Senior Vice President promised "AMD will provide additional updates on both our analysis of these issues and the related mitigation plans in the coming weeks," well its been 8 months and they opted for a total blackout; 8 months and the greatest chipset level vulnerabilities in AMD's history are apparently spreading freely and openly around the globe. It appears AMD doesn't have any concern for their customers safety, be it corporate, business, or power-users. Such a vulnerability is catastrophic and could result in untold fraud, theft, espionage, you name it. Snowden warned AMD and asked them to opensource PSP for this very reason. They didn't listen:


Read AMD's own public statement and report on these verified vulnerabilities: https://community.amd.com/community...amd-technical-assessment-of-cts-labs-research

There is nothing else to be found on their community forum anywhere.

Problem Description & Method of Exploitation "Attacker who already has compromised the security of a system updates flash to corrupt its contents. AMD Secure Processor (PSP) checks do not detect the corruption. "

Bear in mind:

“In a recent survey it was reported that 90 percent of all businesses suffered some sort of computer hack over the past 12 months and 77 percent of these companies felt that they were successfully attacked several times over the same period of time.”
https://stellarbluetechnologies.com/2015/08/4-scary-hacking-statistics/

A 10 year old could pull this off.

Evidence Suggests Report on AMD Security Was Financially Motivated
https://wccftech.com/report-alleges-amd-ryzen-epyc-cpus-suffer-13-fatal-security-flaws/

These are hardware level exploits that remain persistent after windows reinstall, format etc.


 
Last edited:
Joined
Oct 17, 2012
Messages
9,781 (2.33/day)
Location
Massachusetts
System Name Americas cure is the death of Social Justice & Political Correctness
Processor i7-11700K
Motherboard Asrock Z590 Extreme wifi 6E
Cooling Noctua NH-U12A
Memory 32GB Corsair RGB fancy boi 5000
Video Card(s) RTX 3090 Reference
Storage Samsung 970 Evo 1Tb + Samsung 970 Evo 500Gb
Display(s) Dell - 27" LED QHD G-SYNC x2
Case Fractal Design Meshify-C
Audio Device(s) on board
Power Supply Seasonic Focus+ Gold 1000 Watt
Mouse Logitech G502 spectrum
Keyboard AZIO MGK-1 RGB (Kaith Blue)
Software Win 10 Professional 64 bit
Benchmark Scores the MLGeesiest
Oh boy, you're going to find out (like I did), that any type of negative comment towards AMD (truthful or not) is like insulting the pope inside of a church.

Get ready.... I can already hear the feverish typing Of keyboards as i typ this.....:D
 
Joined
Dec 14, 2013
Messages
2,615 (0.69/day)
Location
Alabama
Processor Ryzen 2700X
Motherboard X470 Tachi Ultimate
Cooling Scythe Big Shuriken 3
Memory C.R.S.
Video Card(s) Radeon VII
Software Win 7
Benchmark Scores Never high enough
Clackity-Clackity-Clackity-Clackity-Clackity-Clackity-Clackity-Clackity-Clackity-Clackity-.........

You've just stirred up a huge nest of mechanical keyboards........ And they ain't happy.
 

rugabunda

New Member
Joined
May 22, 2018
Messages
24 (0.01/day)
Do police, intelligence, banking institutions, international corporations know about this before they buy these chips? If Israeli's can do this, any child could. Tens, hundreds of millions of people will not be happy when they realize AMD's chipsets resulted in the losses of billions of dollars, or worse. At least Intel actually made their vulnerabilities front page news, and initiated steps to mitigate against Intel_ME exploits. How stupid can these people be? Please prove me wrong. This is going to blow up in their faces.
 
Last edited:
Joined
Mar 18, 2015
Messages
2,960 (0.89/day)
Location
Long Island
I can't think of a reason to care ... since the 1st of these stories was written for both Intel and AMds choips, I still haven't found the sad story where someone suffered any inconvenience as a resuklt of any of these. Vulnerabilities which require me to do 6 stoopid things and a hacker 10 really smart things after seeking me out don't really put fear in my heart.
 
Joined
Jul 16, 2014
Messages
8,116 (2.28/day)
Location
SE Michigan
System Name Dumbass
Processor AMD Ryzen 7800X3D
Motherboard ASUS TUF gaming B650
Cooling Artic Liquid Freezer 2 - 420mm
Memory G.Skill Sniper 32gb DDR5 6000
Video Card(s) GreenTeam 4070 ti super 16gb
Storage Samsung EVO 500gb & 1Tb, 2tb HDD, 500gb WD Black
Display(s) 1x Nixeus NX_EDG27, 2x Dell S2440L (16:9)
Case Phanteks Enthoo Primo w/8 140mm SP Fans
Audio Device(s) onboard (realtek?) - SPKRS:Logitech Z623 200w 2.1
Power Supply Corsair HX1000i
Mouse Steeseries Esports Wireless
Keyboard Corsair K100
Software windows 10 H
Benchmark Scores https://i.imgur.com/aoz3vWY.jpg?2
Oh geez here we go again.

5 bucks if you can name the people that own and run CTS. Then I'll show you a hedge fund manager looking to manipulate AMD stock.

doesnt make what they found any less true tho.
 

eidairaman1

The Exiled Airman
Joined
Jul 2, 2007
Messages
40,435 (6.59/day)
Location
Republic of Texas (True Patriot)
System Name PCGOD
Processor AMD FX 8350@ 5.0GHz
Motherboard Asus TUF 990FX Sabertooth R2 2901 Bios
Cooling Scythe Ashura, 2×BitFenix 230mm Spectre Pro LED (Blue,Green), 2x BitFenix 140mm Spectre Pro LED
Memory 16 GB Gskill Ripjaws X 2133 (2400 OC, 10-10-12-20-20, 1T, 1.65V)
Video Card(s) AMD Radeon 290 Sapphire Vapor-X
Storage Samsung 840 Pro 256GB, WD Velociraptor 1TB
Display(s) NEC Multisync LCD 1700V (Display Port Adapter)
Case AeroCool Xpredator Evil Blue Edition
Audio Device(s) Creative Labs Sound Blaster ZxR
Power Supply Seasonic 1250 XM2 Series (XP3)
Mouse Roccat Kone XTD
Keyboard Roccat Ryos MK Pro
Software Windows 7 Pro 64
Do police, intelligence, banking institutions, international corporations know about this before they buy these chips? If Israeli's can do this, any child could. Tens, hundreds of millions of people will not be happy when they realize AMD's chipsets resulted in the losses of billions of dollars, or worse. At least Intel actually made their vulnerabilities front page news, and initiated steps to mitigate against Intel_ME exploits. How stupid can these people be? Please prove me wrong. This is going to blow up in their faces.
Intel hid their vulnerabilities for over a decade.
 
Joined
Aug 20, 2007
Messages
20,759 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
I thought the majority of these were patched via BIOS updates? There certainly were PSP firmware updates issued.

Can anyone more knowledgeable on the AMD side confirm or deny? AFAIK last I heard the vast majority of these were patched, or on their way to being patched.

A 10 year old could pull this off.

If a 10 year old has local access, maybe. It's not really that trivial.
 
Joined
Jul 16, 2014
Messages
8,116 (2.28/day)
Location
SE Michigan
System Name Dumbass
Processor AMD Ryzen 7800X3D
Motherboard ASUS TUF gaming B650
Cooling Artic Liquid Freezer 2 - 420mm
Memory G.Skill Sniper 32gb DDR5 6000
Video Card(s) GreenTeam 4070 ti super 16gb
Storage Samsung EVO 500gb & 1Tb, 2tb HDD, 500gb WD Black
Display(s) 1x Nixeus NX_EDG27, 2x Dell S2440L (16:9)
Case Phanteks Enthoo Primo w/8 140mm SP Fans
Audio Device(s) onboard (realtek?) - SPKRS:Logitech Z623 200w 2.1
Power Supply Corsair HX1000i
Mouse Steeseries Esports Wireless
Keyboard Corsair K100
Software windows 10 H
Benchmark Scores https://i.imgur.com/aoz3vWY.jpg?2
A second look at this post makes me think, its a PR stunt. FUD?
 
Joined
Dec 30, 2010
Messages
2,087 (0.43/day)
I believe that AMD was not opensourcing their PSP because it proberly contains technology that has patents or something. But they actually released certain CPU microcode updates which prevents such exploits. Now i am missing in any of your posts if these where covered or not.
 
Joined
Aug 20, 2007
Messages
20,759 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
A second look at this post makes me think, its a PR stunt. FUD?

This user was PMing me and my client while we were dealing with the nasty UEFI malware. I'd categorize him more as a very... I don't know the diplomatic term so I'm just going to say "worry wort."

I don't think this is a legit issue.
 
Joined
Jul 16, 2014
Messages
8,116 (2.28/day)
Location
SE Michigan
System Name Dumbass
Processor AMD Ryzen 7800X3D
Motherboard ASUS TUF gaming B650
Cooling Artic Liquid Freezer 2 - 420mm
Memory G.Skill Sniper 32gb DDR5 6000
Video Card(s) GreenTeam 4070 ti super 16gb
Storage Samsung EVO 500gb & 1Tb, 2tb HDD, 500gb WD Black
Display(s) 1x Nixeus NX_EDG27, 2x Dell S2440L (16:9)
Case Phanteks Enthoo Primo w/8 140mm SP Fans
Audio Device(s) onboard (realtek?) - SPKRS:Logitech Z623 200w 2.1
Power Supply Corsair HX1000i
Mouse Steeseries Esports Wireless
Keyboard Corsair K100
Software windows 10 H
Benchmark Scores https://i.imgur.com/aoz3vWY.jpg?2
I thought the majority of these were patched via BIOS updates? There certainly were PSP firmware updates issued.

Can anyone more knowledgeable on the AMD side confirm or deny? AFAIK last I heard the vast majority of these were patched, or on their way to being patched.



If a 10 year old has local access, maybe. It's not really that trivial.
Admin access i think it was
 
Joined
Aug 20, 2007
Messages
20,759 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
Admin access i think it was

Well give me any modern windows box with a local console and privilege escalation is only a matter of time. But yeah.
 
Joined
Mar 10, 2010
Messages
11,878 (2.31/day)
Location
Manchester uk
System Name RyzenGtEvo/ Asus strix scar II
Processor Amd R5 5900X/ Intel 8750H
Motherboard Crosshair hero8 impact/Asus
Cooling 360EK extreme rad+ 360$EK slim all push, cpu ek suprim Gpu full cover all EK
Memory Corsair Vengeance Rgb pro 3600cas14 16Gb in four sticks./16Gb/16GB
Video Card(s) Powercolour RX7900XT Reference/Rtx 2060
Storage Silicon power 2TB nvme/8Tb external/1Tb samsung Evo nvme 2Tb sata ssd/1Tb nvme
Display(s) Samsung UAE28"850R 4k freesync.dell shiter
Case Lianli 011 dynamic/strix scar2
Audio Device(s) Xfi creative 7.1 on board ,Yamaha dts av setup, corsair void pro headset
Power Supply corsair 1200Hxi/Asus stock
Mouse Roccat Kova/ Logitech G wireless
Keyboard Roccat Aimo 120
VR HMD Oculus rift
Software Win 10 Pro
Benchmark Scores 8726 vega 3dmark timespy/ laptop Timespy 6506
Do police, intelligence, banking institutions, international corporations know about this before they buy these chips? If Israeli's can do this, any child could. Tens, hundreds of millions of people will not be happy when they realize AMD's chipsets resulted in the losses of billions of dollars, or worse. At least Intel actually made their vulnerabilities front page news, and initiated steps to mitigate against Intel_ME exploits. How stupid can these people be? Please prove me wrong. This is going to blow up in their faces.
What have CTS been upto since?.
 

rugabunda

New Member
Joined
May 22, 2018
Messages
24 (0.01/day)
I believe that AMD was not opensourcing their PSP because it proberly contains technology that has patents or something. But they actually released certain CPU microcode updates which prevents such exploits. Now i am missing in any of your posts if these where covered or not.

Perhaps; They could at the very least, release a patch for users who want to shut down PSP after boot, reducing surface attack vectors. They suggested their ceos were looking into just that, or open-sourcing it to libreboot. I'll see if i can find that source. They claimed they would go into more detail in the coming weeks with the mitigations, that was 8 months ago, and there is not so much as a peep anywhere. If you can find sources on that, please share it here. And yes this is serious stuff.


https://www.reddit.com/r/linux/comments/5xvn4i
 
Last edited:
Joined
Mar 18, 2008
Messages
5,400 (0.92/day)
Location
Australia
System Name Night Rider | Mini LAN PC | Workhorse
Processor AMD R7 5800X3D | Ryzen 1600X | i7 970
Motherboard MSi AM4 Pro Carbon | GA- | Gigabyte EX58-UD5
Cooling Noctua U9S Twin Fan| Stock Cooler, Copper Core)| Big shairkan B
Memory 2x8GB DDR4 G.Skill Ripjaws 3600MHz| 2x8GB Corsair 3000 | 6x2GB DDR3 1300 Corsair
Video Card(s) MSI AMD 6750XT | 6500XT | MSI RX 580 8GB
Storage 1TB WD Black NVME / 250GB SSD /2TB WD Black | 500GB SSD WD, 2x1TB, 1x750 | WD 500 SSD/Seagate 320
Display(s) LG 27" 1440P| Samsung 20" S20C300L/DELL 15" | 22" DELL/19"DELL
Case LIAN LI PC-18 | Mini ATX Case (custom) | Atrix C4 9001
Audio Device(s) Onboard | Onbaord | Onboard
Power Supply Silverstone 850 | Silverstone Mini 450W | Corsair CX-750
Mouse Coolermaster Pro | Rapoo V900 | Gigabyte 6850X
Keyboard MAX Keyboard Nighthawk X8 | Creative Fatal1ty eluminx | Some POS Logitech
Software Windows 10 Pro 64 | Windows 10 Pro 64 | Windows 7 Pro 64/Windows 10 Home
What the heck is this come up again for? it was Fud back then and its fud now, so who cares? the so called issues was so minor and retarded that you would literally needed to be at the PC to do any possible harm to it and required a flashing of the BIOS from memory? another words not going to happen unless your James Bond.
 
Joined
Apr 15, 2009
Messages
1,011 (0.18/day)
Processor Ryzen 9 5900X
Motherboard Gigabyte X570 Aorus Master
Cooling ARCTIC Liquid Freezer II 360 A-RGB
Memory 32 GB Ballistix Elite DDR4-3600 CL16
Video Card(s) XFX 6800 XT Speedster Merc 319 Black
Storage Sabrent Rocket NVMe 4.0 1TB
Display(s) LG 27GL850B x 2 / ASUS MG278Q
Case be quiet! Silent Base 802
Audio Device(s) Sound Blaster AE-7 / Sennheiser HD 660S
Power Supply Seasonic Prime 750W Titanium
Software Windows 11 Pro 64
It's a new member FUD frenzy!
 
Joined
Aug 20, 2007
Messages
20,759 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64

rugabunda

New Member
Joined
May 22, 2018
Messages
24 (0.01/day)
The reddit thread was re-opened here: https://www.reddit.com/r/Amd/comments/9wjhi8
Ok here it is finally... well, thats a good start, but until PSP can be secured permanently by disabling it post boot, or making it open source, it will likely be a continual cat and mouse game...
https://www.tomshardware.com/news/amd-vulnerability-patches-ecosystem-partners,36993.html

Within approximately 30 days of being notified by CTS Labs, AMD released patches to our ecosystem partners mitigating all of the CTS identified vulnerabilities on our EPYC™ platform as well as patches mitigating Chimera across all AMD platforms. These patches are in final testing with our ecosystem partners in advance of being released publicly. We remain on track to begin releasing patches to our ecosystem partners for the other products identified in the report this month. We expect these patches to be released publicly as our ecosystem partners complete their validation work.
 
Joined
Oct 2, 2015
Messages
2,991 (0.96/day)
Location
Argentina
System Name Ciel
Processor AMD Ryzen R5 5600X
Motherboard Asus Tuf Gaming B550 Plus
Cooling ID-Cooling 224-XT Basic
Memory 2x 16GB Kingston Fury 3600MHz@3933MHz
Video Card(s) Gainward Ghost 3060 Ti 8GB + Sapphire Pulse RX 6600 8GB
Storage NVMe Kingston KC3000 2TB + NVMe Toshiba KBG40ZNT256G + HDD WD 4TB
Display(s) AOC Q27G3XMN + Samsung S22F350
Case Cougar MX410 Mesh-G
Audio Device(s) Kingston HyperX Cloud Stinger Core 7.1 Wireless PC
Power Supply Aerocool KCAS-500W
Mouse EVGA X15
Keyboard VSG Alnilam
Software Windows 11
My motherboard lets me do a partial shut down of PSP, that plus the BIOS patches should be enough.
 

btarunr

Editor & Senior Moderator
Staff member
Joined
Oct 9, 2007
Messages
46,354 (7.68/day)
Location
Hyderabad, India
System Name RBMK-1000
Processor AMD Ryzen 7 5700G
Motherboard ASUS ROG Strix B450-E Gaming
Cooling DeepCool Gammax L240 V2
Memory 2x 8GB G.Skill Sniper X
Video Card(s) Palit GeForce RTX 2080 SUPER GameRock
Storage Western Digital Black NVMe 512GB
Display(s) BenQ 1440p 60 Hz 27-inch
Case Corsair Carbide 100R
Audio Device(s) ASUS SupremeFX S1220A
Power Supply Cooler Master MWE Gold 650W
Mouse ASUS ROG Strix Impact
Keyboard Gamdias Hermes E2
Software Windows 11 Pro
What have CTS been upto since?.

Coughing up ungodly amounts of money on interest payments for their shorting positions, if they haven't shorted for scraps already.

I'm closing this thread for flamebait. Feel free to necromance the newspost discussions.
 
Status
Not open for further replies.
Top