Monday, 20 January 2025
24.7 C
Singapore
20.9 C
Thailand
21.1 C
Indonesia
25.9 C
Philippines

Apple silicon vulnerability exposes encryption keys

Discover the recent vulnerability in Apple's M-series chips that allows encryption keys to leak and learn how to protect your device.

International researchers have unearthed a significant vulnerability in Apple’s M-series chips, which can leak encryption keys. This flaw, embedded within the chip’s microarchitectural design, cannot be patched traditionally. Instead, software-based mitigation strategies are necessary, potentially hampering performance. The technical nature of this discovery is best understood by delving into the detailed report by Ars Technica, but a simplified explanation is provided here for clarity.

Understanding the GoFetch attack

The crux of the issue lies in Apple Silicon’s data memory-dependent prefetcher (DMP). This component predicts which memory addresses will likely be needed by running code, enhancing efficiency. However, this predictive mechanism can be manipulated to unveil sensitive data, including encryption keys, through an attack dubbed GoFetch. The researchers’ groundbreaking insight revealed that while the DMP typically only dereferences pointers, attackers can craft inputs that, combined with cryptographic secrets, result in an intermediate state mimicking a pointer under specific conditions. This vulnerability enables the extraction of partial or complete information about the cryptographic secret, undermining the security of constant-time swap primitives and various cryptographic implementations designed to resist chosen-input attacks.

Historical context and mitigation

Interestingly, this is not the first instance of a DMP-related flaw in Apple Silicon; a similar vulnerability, the Augury flaw, was identified in 2022. Although the recent discovery may raise concerns, the practical risk is considered low. Gaining system access and the time required for an attack are significant barriers. Extracting a 2048-bit RSA key took the researchers just under an hour, whereas obtaining a 2048-bit Diffie-Hellman key took over two hours, and a Dilithium-2 key took more than ten hours.

Protecting your devices

Adhering to basic security practices is advisable for users seeking to safeguard their devices against such vulnerabilities. Keeping macOS Gatekeeper enabled and avoiding the installation of apps from unknown sources are essential steps in maintaining security.

In summary, while discovering this flaw in Apple’s M-series chips highlights potential security concerns, the immediate risk to users remains low, thanks to the demanding requirements for executing such an attack. Nonetheless, awareness and adherence to recommended security measures are crucial for protection.

Hot this week

OPPO partners with football prodigy Lamine Yamal as global ambassador

OPPO announces Lamine Yamal as global ambassador, combining football and technology to inspire young people through the "Make Your Moment" campaign.

AI-driven data growth to boost demand for cloud storage, says Seagate survey

AI adoption drives data storage growth, with 53% of Singapore firms expecting cloud storage needs to double by 2028, says Seagate survey.

OPPO partners with Mobile Legends: Bang Bang for a smooth gaming experience on the Reno13 series

OPPO partners with Mobile Legends: Bang Bang for the Reno13 Series, unveiling the MLBB x OPPO Smooth Legend Cup with prizes worth US$10,000+.

Sterra launches dehumidifiers to improve home comfort and air quality

Sterra introduces the Ray and Titan dehumidifiers, offering advanced humidity control and air purification for healthier, more comfortable homes.

How to download your TikTok videos and data before the ban

The Supreme Court has upheld a TikTok ban, and here’s how you can back up your videos and data before it happens.

Genshin Impact developer settles FTC charges with US$20 million fine

Genshin Impact developer Cognosphere agrees to pay a US$20 million fine and implement changes to in-game purchases following FTC charges.

Nintendo leaves the original Donkey Kong Country Returns team out of remaster credits

Nintendo's Donkey Kong Country Returns HD remaster omits the original Retro Studios team from credits, sparking discussions about crediting in gaming.

Instagram to replace square profile grids with rectangles

Instagram is switching to rectangle grids for profiles, moving away from squares. Plus, a new Reels feature shows videos that friends like.

Apple reveals apps removed from U.S. App Store alongside TikTok

Apple lists all apps removed in the U.S. alongside TikTok, including CapCut and Lemon8, citing legal obligations under U.S. law.

Related Articles

Popular Categories