[HN Gopher] Zentool - AMD Zen Microcode Manipulation Utility
___________________________________________________________________
Zentool - AMD Zen Microcode Manipulation Utility
Author : taviso
Score : 27 points
Date : 2025-03-05 21:10 UTC (1 hours ago)
(HTM) web link (github.com)
(TXT) w3m dump (github.com)
| p1mrx wrote:
| > You can use the `resign` command to compensate for the changes
| you made:
|
| How does that work? Did someone figure out AMD's private keys?
| yuriks wrote:
| The intro document mentions
|
| > Here's the thing - the big vendors encrypt and sign their
| updates so that you cannot run your own microcode. A big
| discovery recently means that the authentication scheme is a
| lot weaker than intended, and you can now effectively
| "jailbreak" your CPU!
|
| But there's no further details. I'd love to know about the
| specifics too!
| taviso wrote:
| They accidentally used the example key from AES-CMAC RFC, the
| full details are in the accompanying blog post:
| https://bughunters.google.com/blog/5424842357473280/zen-
| and-...
| AHTERIX5000 wrote:
| This work is related to recently found signing weakness and
| supposedly fake key with resign works with unpatched CPUs.
| dzdt wrote:
| The blog post that explains the exploit and how this whole thing
| works is at
| https://bughunters.google.com/blog/5424842357473280/zen-and-...
| BonusPlay wrote:
| Both AMD and Google note, that Zen[1-4] are affected, but what
| changed about Zen5? According to the timeline, it released before
| Google notified AMD [1].
|
| Is it using different keys, but same scheme (and could possibly
| be broken via side-channels as noted in the article)? Or perhaps
| AMD notices something and changed up the microcode? Some
| clarification on that part would be nice.
|
| [1] https://github.com/google/security-
| research/security/advisor...
___________________________________________________________________
(page generated 2025-03-05 23:00 UTC)