Here we are - 3600 which was still under manufacture 2-3 years ago are not get patched. Shame on you AMD, if it is true.

  • ducking_donuts@lemm.ee
    link
    fedilink
    English
    arrow-up
    61
    ·
    1 month ago

    The good news is that in order to exploit the new vulnerability, the attacker first has to obtain kernel level access to the system somehow - by exploiting some other vulnerabilities perhaps.

    The bad news is once Sinkclose attack is performed, it can be hard to detect and mitigate: it can even survive an OS reinstall.

    • scoutFDT@lemm.ee
      link
      fedilink
      English
      arrow-up
      50
      arrow-down
      1
      ·
      1 month ago

      So basically what you are saying is we just need one pvp game with kernel level anti cheat to fuck up somewhere… yeah I’m sure that’s not going to happen.

      • raspberriesareyummy@lemmy.world
        link
        fedilink
        English
        arrow-up
        5
        arrow-down
        12
        ·
        1 month ago

        we just need one pvp game with kernel level anti cheat

        Leaving aside that security patches should be done, if you install that kind of game on a system where you have any data worth protecting, you’re a dumb ass mtherfcker. Sorry, but seriously, that’s just how it is.

        • scutiger@lemmy.world
          link
          fedilink
          English
          arrow-up
          6
          ·
          1 month ago

          Ignorance is not stupidity.

          Despite this being reported on tech news, most people won’t even be aware that it’s a thing because most people won’t actually read about it. And the majority of gamers probably don’t even know what a kernel is or why an anti-cheat with elevated privileges would be a bad thing.

          Most people buy their computers with Windows preinstalled and probably couldn’t tell you if the CPU is Intel or AMD.

          • raspberriesareyummy@lemmy.world
            link
            fedilink
            English
            arrow-up
            3
            ·
            1 month ago

            Okay, fair point, let me rephrase: if someone knows what kernel (admin) level execution means, and installs a game that requires this on a computer where they keep important data, they are a dumbass mtherfcker :) Generally speaking though: most people shouldn’t be allowed to use technology - humans are unbelievably stupid for the most part.

            • WhyJiffie@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              1
              ·
              1 month ago

              Kernel level and admin level is not the same thing. For example on windows, you can’t really write your own kernel driver, and on Linux even root can’t do everything if capabilities have been revoked.

              • raspberriesareyummy@lemmy.world
                link
                fedilink
                English
                arrow-up
                1
                ·
                1 month ago

                For the purpose of protecting important data, the distinction really doesn’t matter. And the good old xkcd comic has a point - for many people, all relevant data is in the user’s accessible storage area anyways. Hence me running almost all internet applications and steam in a jail.

    • JASN_DE@lemmy.world
      link
      fedilink
      English
      arrow-up
      11
      arrow-down
      1
      ·
      1 month ago

      The other bad news: there are so many vulnerabilities on all systems which can be used to gain root-level access, it’s just a matter of time. Also, even future vulnerabilities will be an issue, as the underlying Sinkclose attacks will still work.