The researchers discovered that AMD had been using a publicly available example key from NIST documentation since Zen 1,
lol… sigh…
Submitted 5 weeks ago by floofloof@lemmy.ca to cybersecurity@infosec.pub
https://www.techspot.com/news/107074-google-researchers-uncover-critical-security-flaw-amd-zen.html
The researchers discovered that AMD had been using a publicly available example key from NIST documentation since Zen 1,
lol… sigh…
Just like all the BIOSes that have turned out to be using example keys called things like TEST ONLY - NOT FOR PRODUCTION, rendering Secure Boot not.
cron@feddit.org 5 weeks ago
I wish these sorts of errors were not that common.