New hardware device can RAM into encrypted memory, expose your data
Attackers would need physical access to the server to pull off the DDR5 trick
Researchers at KU Leuven, ETH Zurich, Durham University, and Google have discovered a weakness in modern encryption hardware that allows attackers with physical access to unencrypted data in protected memory during confidential computing. This flaw affects various hardware-based confidential computing technologies, such as Intel TDX, Scalable SGX, and AMD SEV-SNP.
To exploit this vulnerability, the researchers developed a small hardware device called DDRop, which interferes with DDR5 write operations by corrupting commands on the high-speed DDR5 memory bus. This enables the attacker to drop writes to encrypted memory, causing the protected virtual machine to compute on old data that decrypts correctly.
The researchers demonstrated that DDRop can force protected VMs into debug mode and read private memory in plaintext, and forge attestation reports, making backdoored VMs appear trustworthy. The attack can be executed in under two minutes and doesn't require crashing the machine. While Intel and AMD have not planned any mitigations for this attack, the researchers released the complete interposer design as open-source hardware.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.