DDRop Attack Uses $159 Hardware to Break Cloud Confidential Computing Protections
Researchers from KU Leuven, ETH Zurich, Durham University, and Google have disclosed a hardware attack called DDRop that can compromise confidential computing protections used in Intel TDX and AMD SEV-SNP systems. The attack uses a custom-built circuit board costing just $159, placed between the CPU and DDR5 memory, which silently drops write commands to keep stale data in memory without triggering encryption alerts. By exploiting this weakness, attackers can gain full control of protected virtual machines and forge attestation — making a VM falsely appear to be running unaltered code. The attack requires both software-level server access and brief physical access to install the interposer hardware. Intel and AMD acknowledged the findings but stated physical-access scenarios fall outside their threat model, and no simple software fix is possible given the architectural nature of the flaw.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in