Thursday, 19 December 2024
27.8 C
Singapore

Apple silicon vulnerability exposes encryption keys

Discover the recent vulnerability in Apple's M-series chips that allows encryption keys to leak and learn how to protect your device.

International researchers have unearthed a significant vulnerability in ‘s M-series chips, which can leak encryption keys. This flaw, embedded within the chip’s microarchitectural design, cannot be patched traditionally. Instead, software-based mitigation strategies are necessary, potentially hampering performance. The technical nature of this discovery is best understood by delving into the detailed report by Ars Technica, but a simplified explanation is provided here for clarity.

Understanding the GoFetch attack

The crux of the issue lies in Apple Silicon’s data memory-dependent prefetcher (DMP). This component predicts which memory addresses will likely be needed by running code, enhancing efficiency. However, this predictive mechanism can be manipulated to unveil sensitive data, including encryption keys, through an attack dubbed GoFetch. The researchers’ groundbreaking insight revealed that while the DMP typically only dereferences pointers, attackers can craft inputs that, combined with cryptographic secrets, result in an intermediate state mimicking a pointer under specific conditions. This vulnerability enables the extraction of partial or complete information about the cryptographic secret, undermining the security of constant-time swap primitives and various cryptographic implementations designed to resist chosen-input attacks.

Historical context and mitigation

Interestingly, this is not the first instance of a DMP-related flaw in Apple Silicon; a similar vulnerability, the Augury flaw, was identified in 2022. Although the recent discovery may raise concerns, the practical risk is considered low. Gaining system access and the time required for an attack are significant barriers. Extracting a 2048-bit RSA key took the researchers just under an hour, whereas obtaining a 2048-bit Diffie-Hellman key took over two hours, and a Dilithium-2 key took more than ten hours.

Protecting your devices

Adhering to basic security practices is advisable for users seeking to safeguard their devices against such vulnerabilities. Keeping Gatekeeper enabled and avoiding the installation of apps from unknown sources are essential steps in maintaining security.

In summary, while discovering this flaw in Apple’s M-series chips highlights potential security concerns, the immediate risk to users remains low, thanks to the demanding requirements for executing such an attack. Nonetheless, awareness and adherence to recommended security measures are crucial for protection.

Hot this week

WhatsApp introduces new calling features for desktop and mobile users

WhatsApp rolls out group call tools, fun video effects, and improved desktop features to make communication more engaging and seamless.

Huawei unveils Mate X6 foldable phone globally

Huawei’s Mate X6 foldable phone debuts globally with advanced cameras, multitasking displays, and durable design. Learn about its features here.

Microsoft ends Skype credits and phone numbers in favour of subscriptions

Microsoft is discontinuing Skype Credits and Numbers and urging users to adopt subscriptions as it shifts focus from pay-as-you-go features.

LG unveils ThinQ API to boost smart home innovation

LG opens its ThinQ API to developers, enhancing smart home integration and functionality across both consumer and business sectors.

Microsoft aims to make the Xbox app the hub for PC gaming

Microsoft updates the Xbox app with 400+ new PC games, a revamped home UI, and improved features to create the ultimate PC gaming hub.

YouTuber reveals possible first look at Nintendo Switch 2 with new magnetic Joy-Cons

YouTuber NerdNest reveals a possible dummy model of the Nintendo Switch 2, showcasing magnetic Joy-Cons, larger screen size, and new features.

PlayStation and AMD collaborate to revolutionise gaming with AI

Sony and AMD partner to bring AI-powered gaming innovations, enhancing graphics and gameplay on PlayStation, PCs, and cloud platforms.

Intel outlines fixes to improve Arrow Lake CPU performance

Intel rolls out fixes for Arrow Lake CPU performance issues, addressing Windows updates, gaming optimisation, and future improvements at CES.

Sandisk unveils bold new rebrand

Sandisk unveils a bold rebrand with a modern logo inspired by data and collaboration, setting the stage for its spinoff from Western Digital.

Related Articles

Popular Categories