Kim Zetter (@KimZetter) on X

X (formerly Twitter) ·

2 min read Original article ↗

Kim Zetter on X: "Newly discovered vuln in Apple M-series chips lets attackers extract secret keys from Macs. "The flaw—a side channel allowing end-to-end key extractions when Apple chips run...widely used cryptographic protocols—can’t be patched" https://t.co/yjQTogcIzk"

  • user avatar

    Newly discovered vuln in Apple M-series chips lets attackers extract secret keys from Macs. "The flaw—a side channel allowing end-to-end key extractions when Apple chips run...widely used cryptographic protocols—can’t be patched"

  • user avatar

    user avatar

    "it can only be mitigated by building defenses into third-party cryptographic software that could drastically degrade M-series performance when executing cryptographic operations, particularly on the earlier M1 and M2 generations...."

    user avatar

    "The vulnerability can be exploited when the targeted cryptographic operation and the malicious application with normal user system privileges run on the same CPU cluster."

    user avatar

    Demo video of the Apple M-Series vuln here:

    user avatar

    The "GoFetch" attack "requires less than an hour to extract a 2048-bit RSA key and a little over 2 hours to extract a 2048-bit Diffie-Hellman key. The attack takes 54 minutes to extract the material required to assemble a Kyber-512 key and about 10 hrs for a Dilithium-2 key"

    user avatar

    People seem to be imagining this is worse than it probably is, so I've written a piece that hopefully explains it in clear language what the problem is and what's at stake.

  • user avatar

    Wow this is bigger news than the anti trust