Our second attack #WeSee to appear @IEEESSP breaks AMD SEV-SNP by sending an interrupt specially introduced for SEV. Starting from a kernel read to arbitrary code injection, we gain a root shell.
Details & Demo at
https://t.co/DWLEATKnt9
Our first attack #Heckler to appear @USENIXSecurity breaks Intel TDX and AMD SEV-SNP by sending interrupts that trigger existing handlers to change the register state and variables in userspace. We break sshd, sudo, and other apps
Details & Demo at https://t.co/5QQmANpTSy
Can a malicious cloud provider send bad notifications to break confidential VMs?
Disclosing #AhoiAttacks that break confidential computing offered by AMD SEV-SNP and Intel TDX by abusing interrupt delivery.
Check our @USENIXSecurity & @IEEESSP papers.
https://t.co/wxr7rBWX7U
Had a great time presenting our latest work, Acai, at the ZTHA workshop.
Acai enhances Arm CCA, enabling confidential VMs to securely use accelerators like GPUs & FPGAs.
Check our Usenix Security'24 paper: https://t.co/94k83zw336
Acai is open source: https://t.co/AOxBpZTHl8
Do users have complete control over their smartphone?
Apple and Google cite technical reasons to control what users, developers, and governments can do on phones.
We are building Sovereign Smartphones to address this.
A recent article explains our work:
https://t.co/GwtyZXjcsR
An international research team whose members include an ETH Zurich professor has revealed a vulnerability in the #SecurityArchitecture of Intel #processors. Until July, Microsoft and Google products were also affected. @CSatETH@NUSingapore https://t.co/WxWqrfGT4a
We have released the details of our upcoming @acm_ccs 2021 paper about a new software attack on SGX
Our attack, SmashEx, exploits reentrancy bugs in enclave exception handling
Check out our webpage for technical details:
https://t.co/BJjoNS9rU8
@jhcui24@corankyu@prateekatcs