Sunday, March 26, 2023
  • Login
ShanelDubai
  • Home
  • News
    • All
    • Politics
    • Science
    • World
    Sorry, UFO Hunters–You Might Just Be Looking at a Spy Balloon

    Sorry, UFO Hunters–You Might Just Be Looking at a Spy Balloon

    Evolution Turns These Knobs to Make a Hummingbird Hyperquick and a Cavefish Sluggishly Slow

    Evolution Turns These Knobs to Make a Hummingbird Hyperquick and a Cavefish Sluggishly Slow

    How the U.S. Is Planning to Boost Floating Wind Power

    How the U.S. Is Planning to Boost Floating Wind Power

    Building Resilience in the Face of Climate Change [Sponsored]

    Building Resilience in the Face of Climate Change [Sponsored]

    JWST Discovers Enormous Distant Galaxies That Should Not Exist

    JWST Discovers Enormous Distant Galaxies That Should Not Exist

    Another Patient Is Free of HIV after Receiving Virus-Resistant Cells

    Another Patient Is Free of HIV after Receiving Virus-Resistant Cells

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Tech
    • All
    • Gadget
    • Mobile

    Hunger Games Prequel Ballad of Songbirds & Snakes New Poster

    1988 David Cronenberg, Jeremy Irons Retro Review

    HBO Max Clone High Revival First Look: Images and New Casting

    No TNG Reunion Without Data

    Sci-Fi Animated Short About a Robot Revolution: Seniors 3000

    The Past Four Months Have Been Rough on Rockets—Especially New Ones

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
  • Entertainment
    • All
    • Gaming
    • Movie
    • Music
    • Sports

    Elden Ring’s Official Strategy Guide Is Coming In Two Volumes, Both Can Be Preordered Now

    Homeworld 3 Delayed to 2023 to Help Protect the Health of Developers

    Superpowered Action-RPG Superfuse Is Coming to Early Access This Fall – IGN Expo 2022

    Cuphead: The Delicious Last Course – First Impressions

    Street Fighter 6 Will Have Character-Specific Taunts – Including Making Fun of Hadouken to Ryu

    How Sonic Frontiers Came to Be an ‘Open-Zone’ Game | IGN First

  • Lifestyle
    • All
    • Fashion
    • Food
    • Health
    • Travel

    Leftovers: Halo Top pops into froyo treats; Takis takes out the spice with nacho cheese snacks

    Momofuku Goods raises $17.5M | Food Dive

    Tapioca starch sweetener gets GRAS status from the FDA

    Nestlé says less than 40% of its sales come from food and beverage offerings considered healthy

    Biotechnology should be used to improve nutrition, sustainability and resiliency of food, Biden report says

    PepsiCo invests $216M into farmer partnerships for regenerative agriculture

    Trending Tags

    • Golden Globes
    • Game of Thrones
    • MotoGP 2017
    • eSports
    • Fashion Week
  • Cooking
  • Health and Fitness
  • Hotels
  • Sports
  • Nightlife
  • Shopping
  • Tourist Attractions
  • Gulf news
  • Turkey
  • YT video
No Result
View All Result
  • Home
  • News
    • All
    • Politics
    • Science
    • World
    Sorry, UFO Hunters–You Might Just Be Looking at a Spy Balloon

    Sorry, UFO Hunters–You Might Just Be Looking at a Spy Balloon

    Evolution Turns These Knobs to Make a Hummingbird Hyperquick and a Cavefish Sluggishly Slow

    Evolution Turns These Knobs to Make a Hummingbird Hyperquick and a Cavefish Sluggishly Slow

    How the U.S. Is Planning to Boost Floating Wind Power

    How the U.S. Is Planning to Boost Floating Wind Power

    Building Resilience in the Face of Climate Change [Sponsored]

    Building Resilience in the Face of Climate Change [Sponsored]

    JWST Discovers Enormous Distant Galaxies That Should Not Exist

    JWST Discovers Enormous Distant Galaxies That Should Not Exist

    Another Patient Is Free of HIV after Receiving Virus-Resistant Cells

    Another Patient Is Free of HIV after Receiving Virus-Resistant Cells

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Tech
    • All
    • Gadget
    • Mobile

    Hunger Games Prequel Ballad of Songbirds & Snakes New Poster

    1988 David Cronenberg, Jeremy Irons Retro Review

    HBO Max Clone High Revival First Look: Images and New Casting

    No TNG Reunion Without Data

    Sci-Fi Animated Short About a Robot Revolution: Seniors 3000

    The Past Four Months Have Been Rough on Rockets—Especially New Ones

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
  • Entertainment
    • All
    • Gaming
    • Movie
    • Music
    • Sports

    Elden Ring’s Official Strategy Guide Is Coming In Two Volumes, Both Can Be Preordered Now

    Homeworld 3 Delayed to 2023 to Help Protect the Health of Developers

    Superpowered Action-RPG Superfuse Is Coming to Early Access This Fall – IGN Expo 2022

    Cuphead: The Delicious Last Course – First Impressions

    Street Fighter 6 Will Have Character-Specific Taunts – Including Making Fun of Hadouken to Ryu

    How Sonic Frontiers Came to Be an ‘Open-Zone’ Game | IGN First

  • Lifestyle
    • All
    • Fashion
    • Food
    • Health
    • Travel

    Leftovers: Halo Top pops into froyo treats; Takis takes out the spice with nacho cheese snacks

    Momofuku Goods raises $17.5M | Food Dive

    Tapioca starch sweetener gets GRAS status from the FDA

    Nestlé says less than 40% of its sales come from food and beverage offerings considered healthy

    Biotechnology should be used to improve nutrition, sustainability and resiliency of food, Biden report says

    PepsiCo invests $216M into farmer partnerships for regenerative agriculture

    Trending Tags

    • Golden Globes
    • Game of Thrones
    • MotoGP 2017
    • eSports
    • Fashion Week
  • Cooking
  • Health and Fitness
  • Hotels
  • Sports
  • Nightlife
  • Shopping
  • Tourist Attractions
  • Gulf news
  • Turkey
  • YT video
No Result
View All Result
Shanel Dubai
No Result
View All Result
Home Tech Gadget

Newly Discovered Apple M1 Security Flaw is Unpatchable

shaneldubai by shaneldubai
June 10, 2022
in Gadget
0
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter


MacBook Air

Photo: Joanna Nelius/Gizmodo

Apple’s blisteringly fast and remarkably efficient M1 chips have been the catalysts behind a recent MacBook resurgence, but MIT security researchers have found a chink in their armor.

MIT Computer Science & Artificial Intelligence Laboratory (CSAIL) scientists revealed in a recent paper a vulnerability in what they call the “last line of security” for the M1 chip. The flaw could theoretically give bad actors a door to gain full access to the core operating system kernel.

Before I go any further, M1 MacBook owners don’t need to worry about having their sensitive data stolen. While this is a severe vulnerability that will need to be addressed, certain unlikely conditions need to be in place for it to work. Foremost, the system under attack needs to have an existing memory corruption bug. As such, the scientists say there is “no cause for immediate alarm.”

For its part, Apple thanked the researchers in a statement to TechCrunch but emphasized that the “issue” doesn’t pose an immediate risk to MacBook owners.

“We want to thank the researchers for their collaboration as this proof of concept advances our understanding of these techniques,” Apple said. “Based on our analysis as well as the details shared with us by the researchers, we have concluded this issue does not pose an immediate risk to our users and is insufficient to bypass operating system security protections on its own.”

G/O Media may get a commission

Samsung 65" QLED Smart TV QN95B

Free Mounting Service

Samsung 65″ QLED Smart TV QN95B

The ultimate 4K experience
Brilliant details shine even in daylight with Quantum Matrix Technology. Powered by a huge grid of Samsung’s ultra-precise Quantum Mini LEDs, it takes exact control of the individual zones of light in your picture for breathtaking color and contrast.

Getting into the technical bits, Apple’s M1 chip uses something called Pointer Authentication to detect and guard against unexpected changes in memory. MIT calls this the “last line of defense,” and says it can snuff out bugs that would normally compromise a system and leak private information. It does this using “PACS,” or pointer authentication code (PAC) that checks for unexpected changes resulting from an attack. A PAC, or a cryptographic hash used as a signature, is made when a program is deemed to be safe.

As the researchers discovered, this line of defense can be broken. That’s where MIT’s PACMAN attack comes in. It guesses the value of a PAC using a hardware device, meaning a software patch won’t fix the program. There are many possible values of a PAC, but with a device that reveals whether a guess is correct or false, you can try them all until you get the right one without leaving any trace. In this scenario, the ghosts win.

“The idea behind pointer authentication is that if all else has failed, you still can rely on it to prevent attackers from gaining control of your system. We’ve shown that pointer authentication as a last line of defense isn’t as absolute as we once thought it was,” said MIT CSAIL Ph.D. student Joseph Ravichandran and co-lead author of the paper.

“When pointer authentication was introduced, a whole category of bugs suddenly became a lot harder to use for attacks. With PACMAN making these bugs more serious, the overall attack surface could be a lot larger,” Ravichandran added.

Since pointer authentication is used to protect the core OS kernel, bypassing it could give bad actors access to the sensitive parts of a system. As the researchers note, “An attacker who gains control of the kernel can do whatever they’d like on a device.”

In this proof of concept, the researchers showed that the PACMAN attack could be used to attack the kernel, which has “massive implications for future security work on all ARM systems with pointer authentication enabled. Future CPU designers should take care to consider this attack when building the secure systems of tomorrow,” Ravichandran warned. “Developers should take care to not solely rely on pointer authentication to protect their software.”

Apple uses pointer authentication on all of its ARM-based chips, including the M1, M1 Pro, and M1 Max. MIT said it hasn’t tested this attack on the recently revealed M2 processor set to power the new MacBook Air and MacBook Pro 13. Qualcomm and Samsung have either announced or are set to ship processors that use the security feature.

The researchers outlined three methods for preventing such an attack in the future. One way is by modifying the software so PAC verification results are never done under speculation, meaning an attacker couldn’t go incognito while attempting to infiltrate. Another potential resolution is by defending against PACMAN in the same way Spectre vulnerabilities are being mitigated. And finally, patching memory corruption bugs would ensure this last line of defense isn’t needed.

Apple wins lawsuit over Spectre and Meltdown Security flaws

In related news, a judge dismissed a class-action lawsuit against Apple for allegedly selling customers iPhones and iPads with processors that were vulnerable to the devastating Spectre and Meltdown flaws. US District Judge Edward Davila in San Jose, California deemed the customers failed to prove that they overpaid for devices because Apple knowingly hid defects, as reported by Reuters. They also didn’t provide enough evidence that a security patch pushed out to those devices made them significantly slower.



Source link

Previous Post

Pope Francis postpones Africa visit over knee problem

Next Post

Superpowered Action-RPG Superfuse Is Coming to Early Access This Fall – IGN Expo 2022

shaneldubai

shaneldubai

Next Post

Superpowered Action-RPG Superfuse Is Coming to Early Access This Fall - IGN Expo 2022

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected test

  • 121 Followers
  • 174k Subscribers
  • 23.8k Followers
  • 99 Subscribers
  • Trending
  • Comments
  • Latest

Does Marvin Harrison have a son? Meet Ohio State WR Marvin Harrison Jr., son of Colts’ star receiver

January 1, 2022

Alabama vs. Cincinnati live score, updates, highlights from 2021 College Football Playoff semifinal

December 31, 2021

What a Health Risk Scientist Still Wants to Know About the Ohio Train Derailment

February 17, 2023
Motorola Edge 30 Pro review

Motorola Edge 30 Pro review

April 4, 2022

Hello world!

1

The Legend of Zelda: Breath of the Wild gameplay on the Nintendo Switch

0

Shadow Tactics: Blades of the Shogun Review

0

macOS Sierra review: Mac users get a modest update this year

0

Hunger Games Prequel Ballad of Songbirds & Snakes New Poster

March 25, 2023

1988 David Cronenberg, Jeremy Irons Retro Review

March 25, 2023

HBO Max Clone High Revival First Look: Images and New Casting

March 25, 2023

No TNG Reunion Without Data

March 25, 2023

Recent News

Hunger Games Prequel Ballad of Songbirds & Snakes New Poster

March 25, 2023

1988 David Cronenberg, Jeremy Irons Retro Review

March 25, 2023

HBO Max Clone High Revival First Look: Images and New Casting

March 25, 2023

No TNG Reunion Without Data

March 25, 2023

Follow us

Browse by Category

  • Cooking
  • Dubai
  • Entertainment
  • Fashion
  • Food
  • Gadget
  • Gaming
  • Health
  • Health and Fitness
  • Hotels
  • Lifestyle
  • Mobile
  • Movie
  • Music
  • News
  • Nightlife
  • Politics
  • Science
  • Shopping
  • Sports
  • Tech
  • Tourist Attractions
  • Travel
  • Turkey
  • World
  • YT video

Recent News

Hunger Games Prequel Ballad of Songbirds & Snakes New Poster

March 25, 2023

1988 David Cronenberg, Jeremy Irons Retro Review

March 25, 2023
  • Dubai
  • Travel
  • Turkey

© 2021 shaneldubai|All right Reversed

No Result
View All Result

© 2021 shaneldubai|All right Reversed

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In