• Home
  • Privacy Policy
  • About Us
  • Contact Us
  • Live TV
  • Canadian Radio
  • USA Radio
  • forum
  • Terms&Conditions
Monday, August 15, 2022
Morning News
No Result
View All Result
  • Login
  • Register
  • Home
  • News
    • Local
      • Toronto
      • Vancouver
    • National
    • World
  • Business
    • Economy
    • Marketing
    • Finance
    • Ideas
  • Investing
    • Market News
    • Stocks Market
    • Cryptocurrency
  • Real Estate
    • The house Market
    • Toronto House
    • Vancouver House
  • Politics
  • Opinion
  • Entertainment
  • Sports
  • Life
    • Fashion
    • Food
    • Health
      • Nutrition
      • Health News
    • Style
    • Travel
      • Tourism News
      • Airline News
      • Hotel News
      • Food & Beverage Travel News
      • Cruise News
  • Technology
    • Automotive
    • Computer Sciences
    • Consumer & Gadgets
    • Electronics & Semiconductors
    • Engineering
    • Energy & Green Tech
    • Business-consumer-gadgets
    • Hardware
    • Hi Tech & Innovation
    • Internet
    • Machine learning & AI
    • Robotics
    • Software
    • Security
    • Telecom
  • Apps
    • Live TV
    • Canadian Radio
    • USA Radio
    • forum
  • Home
  • News
    • Local
      • Toronto
      • Vancouver
    • National
    • World
  • Business
    • Economy
    • Marketing
    • Finance
    • Ideas
  • Investing
    • Market News
    • Stocks Market
    • Cryptocurrency
  • Real Estate
    • The house Market
    • Toronto House
    • Vancouver House
  • Politics
  • Opinion
  • Entertainment
  • Sports
  • Life
    • Fashion
    • Food
    • Health
      • Nutrition
      • Health News
    • Style
    • Travel
      • Tourism News
      • Airline News
      • Hotel News
      • Food & Beverage Travel News
      • Cruise News
  • Technology
    • Automotive
    • Computer Sciences
    • Consumer & Gadgets
    • Electronics & Semiconductors
    • Engineering
    • Energy & Green Tech
    • Business-consumer-gadgets
    • Hardware
    • Hi Tech & Innovation
    • Internet
    • Machine learning & AI
    • Robotics
    • Software
    • Security
    • Telecom
  • Apps
    • Live TV
    • Canadian Radio
    • USA Radio
    • forum
No Result
View All Result
Morning News
No Result
View All Result
Home Technology Hardware

Researchers discover a new hardware vulnerability in the Apple M1 chip

by Author
June 14, 2022
in Hardware, Security
Reading Time: 4 mins read
0 0
A A
0
1
SHARES
10
VIEWS
FacebookTwitterLinkedinRedditWhatsapp
pacman
Credit: Pixabay/CC0 Public Domain

William Shakespeare might have been talking about Apple’s recently released M1 chip via his prose in A Midnight Summer’s Dream: “And though she be but little, she is fierce.”

Well, probably not, but it fits: Apple’s software runs on the little masterful squares made of in-house silicon, resulting in amazing performance with industry-leading power efficiency. Despite their potency, over the years there’s been no shortage of vulnerability grievances, as fears of sensitive data leaks and personal information abound. More recently, the celebrity-like chip itself was found to have a security flaw of its own, which was quickly deemed harmless.

The M1 chip uses a feature called “Pointer Authentication,” which acts as a last line of defense against typical software vulnerabilities. With Pointer Authentication enabled, bugs that normally could compromise a system or leak private information are stopped dead in their tracks. Now, researchers from MIT’s Computer Science and Artificial Intelligence Laboratory have found a crack: their novel hardware attack, called “PACMAN” shows that Pointer Authentication can be defeated without even leaving a trace. Moreover, PACMAN utilizes a hardware mechanism, so no software patch can ever fix it.

A pointer authentication code, or “PAC” for short, is a signature that confirms that the state of the program hasn’t been changed maliciously. Enter the PACMAN attack. The team showed that it’s possible to “guess” a value for the PAC, and reveal whether the guess was correct or not via a hardware side channel. And since there are only so many possible values for the PAC, they found that it’s possible to try them all to find the correct one. Most importantly, since the guesses all happen under speculative execution, the attack leaves no trace.

“The idea behind pointer authentication is that if all else has failed, you still can rely on it to prevent attackers from gaining control of your system. We’ve shown that pointer authentication as a last line of defense isn’t as absolute as we once thought it was,” says MIT CSAIL Ph.D. student Joseph Ravichandran, co-lead author of a new paper about PACMAN. “When pointer authentication was introduced, a whole category of bugs suddenly became a lot harder to use for attacks. With PACMAN making these bugs more serious, the overall attack surface could be a lot larger.”

An attack with hardware and software

Traditionally, hardware and software attacks have lived somewhat separate lives. People see their software bugs as software bugs and hardware bugs as hardware bugs. There’s this traditional world of architecturally visible software threats—think the malicious phishing attempts, malware, denial-of-service, and the like. On the hardware side, there’s the much-talked-about 2018 Spectre and Meltdown realm, where you’re manipulating microarchitectural structures to steal data from computers.

The team wanted to see what combining the two might achieve—taking something from the software security world, and breaking a mitigation (a feature that’s designed to protect software), using hardware attacks. “That’s the heart of what PACMAN represents—a new way of thinking about how threat models converge in the Spectre era,” says Ravichandran.

PACMAN isn’t a magic bypass for all security on the M1 chip. PACMAN can only take an existing bug that pointer authentication protects against, and unleash that bug’s true potential for use in an attack by finding the correct PAC. There’s no cause for immediate alarm, the scientists say, as PACMAN cannot compromise a system without an existing software bug.

Pointer authentication is primarily used to protect the core operating system kernel, the most privileged part of the system. An attacker who gains control of the kernel can do whatever they’d like on a device. The team showed that the PACMAN attack even works against the kernel, which has “Massive implications for future security work on all ARM systems with pointer authentication enabled. Future CPU designers should take care to consider this attack when building the secure systems of tomorrow,” says Ravichandran. “Developers should take care to not solely rely on pointer authentication to protect their software.”

“Software vulnerabilities have existed for roughly 30 years now. Researchers have come up with ways to mitigate them using various innovative techniques such as ARM pointer authentication, which we are attacking now. Our work provides insight into how software vulnerabilities that continue to exist as important mitigation methods can be bypassed via hardware attacks,” says MIT Professor and author Mengjia Yan. “It’s a new way to look at this very long-lasting security threat model. Many other mitigation mechanisms exist that are not well studied under this new compounding threat model, so we consider the PACMAN attack as a starting point. We hope PACMAN can inspire more work in this research direction in the community.”

The team will present the paper at the International Symposium on Computer Architecture on June 18th. Ravichandran and Yan wrote the paper alongside first co-author Weon Taek Na, MIT CSAIL PhD student and Jay Lang, MIT undergraduate student.


Explore further

Once overlooked, uninitialized-use ‘bugs’ may provide portal for hacker attacks on Linux


Provided by
MIT Computer Science & Artificial Intelligence Lab

Citation:
Researchers discover a new hardware vulnerability in the Apple M1 chip (2022, June 13)
retrieved 14 June 2022
from https://techxplore.com/news/2022-06-hardware-vulnerability-apple-m1-chip.html
This document is subject to copyright. Apart from any fair dealing for the purpose of private study or research, no
part may be reproduced without the written permission. The content is provided for information purposes only.
Tags: authenticationhardwaresecurity flawsoftware

Related Posts

Consumer & Gadgets

Deepfakes expose vulnerabilities in certain facial recognition technology

3 days ago

Credit: Pixabay/CC0 Public Domain Mobile devices use facial recognition technology to help users quickly and securely unlock their phones, make...

Consumer & Gadgets

Amazon, Oracle shrug off lawmaker fears of abortion data sales

3 days ago

Credit: Unsplash/CC0 Public Domain Amazon.com Inc., Oracle Corp. and other data providers pressed by a group of U.S. lawmakers about...

Next Post
Prince William and Kate Middleton

Prince William And Kate Middleton Are Moving Out Of London

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Daily Popular

Local

Oakville mayor supports creating Canada’s largest municipal park right here

by Author
4 days ago
0
16

Oakville Mayor Rob Burton wants to create Canada’s largest park right here in our own backyard.The new municipal park would...

Read more

Anne Heche To Receive Honour Walk As Organs Are Donated

Two men facing charges after victim of assault at Scarborough restaurant dies in hospital

Tesla has built 3 million vehicles, a third of those in China, Elon Musk says

‘We feel like it’s rent gouging’: Renters meet with Biden administration officials to decry steep increases by landlords

Load More

Popular News

Germany is facing dramatic change in many dimensions all at once

August 13, 2022
38

More power on less land: The push to shrink solar’s footprint

August 8, 2022
34

MornsLive TV

August 13, 2022
34
malvern town centre

Another Toronto mall will be completely demolished to make way for condos

August 4, 2022
98
The teacher was convicted of possessing child pornography in 2021. (File Photo)

Greater Victoria teacher permanently banned from teaching after child porn conviction

August 9, 2022
20
Load More
Shop is live!!!
Shop is live!!!

News Staff Editor

Transform How Your House Look With This Simple Tips

by News-Staff
August 2, 2022
0
44

A home is a place where we can feel safe and loved. It's a place where we can be ourselves,...

Read more
Load More

Most Comment

Fire in Brampton leads to residents being evacuated

March 2, 2022
16

Vanguard adds an ‘impact fund’ that targets social and environmental change

July 18, 2022
11

War means pain for Europe now, later for Russia

July 18, 2022
11

Economics of war: Pain for Europe now, later for Russia

July 18, 2022
11

Joey King Talks Shaved Heads, Wedding Planning & Working With Fiancé Steven Piet: ‘We Just Really Love Spending Time Together’

July 28, 2022
12
Load More

Forums

  • funny
  • investing
  • pics
  • politics
  • sports
  • stocks
  • technology
  • worldnews

Recent Topics

  • U.S.
  • Canada Sports Sporting Made Simple id65
  • Online Sports Dissipated Sites54
  • 679 største udvalg af fodboldtrøjer AdanLo
  • 083 fotballdrakter barn Krystl
  • 051 hvor kan man kjøpe fotballdrakter Michae
  • 346 klassiska fotbollströjor JulieM

Topic Views List

  • Most popular topics
  • Topics with no replies

Recent Replies

  • Funny Dog Videos
  • 346 klassiska fotbollströjor JulieM
  • Home
  • Privacy Policy
  • About Us
  • Contact Us
  • Live TV
  • Canadian Radio
  • USA Radio
  • forum
  • Terms&Conditions

© 2022 All News in One - Morning News by morns.ca.

No Result
View All Result
  • Home
  • News
    • Local
      • Toronto
      • Vancouver
    • National
    • World
  • Business
    • Economy
    • Marketing
    • Finance
    • Ideas
  • Investing
    • Market News
    • Stocks Market
    • Cryptocurrency
  • Real Estate
    • The house Market
    • Toronto House
    • Vancouver House
  • Politics
  • Opinion
  • Entertainment
  • Sports
  • Life
    • Fashion
    • Food
    • Health
      • Nutrition
      • Health News
    • Style
    • Travel
      • Tourism News
      • Airline News
      • Hotel News
      • Food & Beverage Travel News
      • Cruise News
  • Technology
    • Automotive
    • Computer Sciences
    • Consumer & Gadgets
    • Electronics & Semiconductors
    • Engineering
    • Energy & Green Tech
    • Business-consumer-gadgets
    • Hardware
    • Hi Tech & Innovation
    • Internet
    • Machine learning & AI
    • Robotics
    • Software
    • Security
    • Telecom
  • Apps
    • Live TV
    • Canadian Radio
    • USA Radio
    • forum
  • Login
  • Sign Up

© 2022 All News in One - Morning News by morns.ca.

Welcome Back!

Sign In with Facebook
Sign In with Google
Sign In with Linked In
OR

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Sign Up with Facebook
Sign Up with Google
Sign Up with Linked In
OR

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In