Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Technology

Researchers expose cheap hardware flaw that compromises encrypted cloud memory

Scientists built a low-cost DDR5 interposer that, with physical access, can replay stale data and extract plaintext from protected virtual machines.

Researchers from KU Leuven, ETH Zurich, Durham University and Google discovered a design weakness in scalable memory-encryption hardware that does not check whether stored data is fresh. They engineered an inexpensive DDR5 interposer, called DDRop, which sits on the memory bus and silently suppresses write operations, forcing a protected virtual machine to continue processing outdated ciphertext that still decrypts correctly.

In tests on an Intel TDX server, the technique allowed the attackers to place the VM into debug mode, read its memory in plaintext and forge attestation reports, all deterministically within two minutes and without crashing the system. The method works against Intel TDX, Scalable SGX and AMD SEV-SNP, and differs from prior passive attacks by operating at full bus speed. Intel and AMD have acknowledged the vulnerability but consider it out of scope for their cloud security models, and no software or hardware patch is currently available. The researchers released the interposer design as open-source hardware.

Why it matters

It shows that inexpensive physical attacks can undermine the confidentiality guarantees of major cloud secure-computing platforms.

In this story

encrypted memoryDDR5 interposerconfidential computingIntel TDXAMD SEV-SNPreplay attackhardware vulnerabilitycloud securityopen-source hardware
Get the beta ↗