Kim Zetter on X: "Newly discovered vuln in Apple M-series chips lets attackers extract secret keys from Macs. "The flaw—a side channel allowing end-to-end key extractions when Apple chips run...widely used cryptographic protocols—can’t be patched" https://t.co/yjQTogcIzk"
Newly discovered vuln in Apple M-series chips lets attackers extract secret keys from Macs. "The flaw—a side channel allowing end-to-end key extractions when Apple chips run...widely used cryptographic protocols—can’t be patched"
"it can only be mitigated by building defenses into third-party cryptographic software that could drastically degrade M-series performance when executing cryptographic operations, particularly on the earlier M1 and M2 generations...."
"The vulnerability can be exploited when the targeted cryptographic operation and the malicious application with normal user system privileges run on the same CPU cluster."
Demo video of the Apple M-Series vuln here:
The "GoFetch" attack "requires less than an hour to extract a 2048-bit RSA key and a little over 2 hours to extract a 2048-bit Diffie-Hellman key. The attack takes 54 minutes to extract the material required to assemble a Kyber-512 key and about 10 hrs for a Dilithium-2 key"
People seem to be imagining this is worse than it probably is, so I've written a piece that hopefully explains it in clear language what the problem is and what's at stake.