DDRop hardware attack breaks Intel and AMD confidential computing protections
Researchers disclosed DDRop, a hardware attack that defeats the memory protection behind Intel and AMD confidential computing, the technology cloud providers use to keep customer data private even from themselves. These systems encrypt a server's memory but, to cover large amounts of it, skip a guarantee that memory holds its latest value, so old encrypted data still decrypts correctly. Using a memory interposer costing under 200 dollars, DDRop silently drops writes, and the processor reads the stale data as current while the encryption engine notices nothing. On Intel's technology this enables attestation forgery, and on AMD it allows copying one protected page into another. It needs physical access, threatening cloud environments.
- Check
- For confidential-computing workloads, enable available memory-integrity modes on Intel processors, weigh the physical-security assumptions of your cloud or hosting provider, and treat attestation as one control rather than a complete guarantee.
- Affected
- Cloud and hosting environments relying on Intel TDX or SGX or AMD SEV-SNP confidential computing; an attacker with physical access to memory can drop writes to defeat attestation or copy protected pages.
- Fix
- Enable cryptographic memory-integrity modes where the hardware supports them, factor physical-access risk into confidential-computing threat models, follow vendor guidance on stronger future designs, and avoid over-trusting attestation for the most sensitive workloads.