[HN Gopher] Zentool - AMD Zen Microcode Manipulation Utility
       ___________________________________________________________________
        
       Zentool - AMD Zen Microcode Manipulation Utility
        
       Author : taviso
       Score  : 27 points
       Date   : 2025-03-05 21:10 UTC (1 hours ago)
        
 (HTM) web link (github.com)
 (TXT) w3m dump (github.com)
        
       | p1mrx wrote:
       | > You can use the `resign` command to compensate for the changes
       | you made:
       | 
       | How does that work? Did someone figure out AMD's private keys?
        
         | yuriks wrote:
         | The intro document mentions
         | 
         | > Here's the thing - the big vendors encrypt and sign their
         | updates so that you cannot run your own microcode. A big
         | discovery recently means that the authentication scheme is a
         | lot weaker than intended, and you can now effectively
         | "jailbreak" your CPU!
         | 
         | But there's no further details. I'd love to know about the
         | specifics too!
        
           | taviso wrote:
           | They accidentally used the example key from AES-CMAC RFC, the
           | full details are in the accompanying blog post:
           | https://bughunters.google.com/blog/5424842357473280/zen-
           | and-...
        
         | AHTERIX5000 wrote:
         | This work is related to recently found signing weakness and
         | supposedly fake key with resign works with unpatched CPUs.
        
       | dzdt wrote:
       | The blog post that explains the exploit and how this whole thing
       | works is at
       | https://bughunters.google.com/blog/5424842357473280/zen-and-...
        
       | BonusPlay wrote:
       | Both AMD and Google note, that Zen[1-4] are affected, but what
       | changed about Zen5? According to the timeline, it released before
       | Google notified AMD [1].
       | 
       | Is it using different keys, but same scheme (and could possibly
       | be broken via side-channels as noted in the article)? Or perhaps
       | AMD notices something and changed up the microcode? Some
       | clarification on that part would be nice.
       | 
       | [1] https://github.com/google/security-
       | research/security/advisor...
        
       ___________________________________________________________________
       (page generated 2025-03-05 23:00 UTC)