/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers detail an unpatchable vulnerability in Apple's M-series of chips that lets attackers extract secret keys from Macs during cryptographic operations

Fixing newly discovered side channel will likely take a major toll on performance.  —  A newly discovered vulnerability baked …

Ars Technica Dan Goodin

Context & Ripple Effects

This disclosure places Apple silicon in the broader history of processor side channels, where fixes can force a security-versus-performance trade-off. Earlier coverage of ZombieLoad mitigations likewise emphasized that closing a hardware leakage path can reduce performance.

It also precedes a later report of two further Apple silicon side-channel techniques affecting newer chip generations, suggesting that isolation boundaries in high-performance processors remain a recurring research target.

First-order effects

  • Apple must weigh mitigations for affected Macs against the reported likelihood of a substantial performance penalty, because the underlying weakness cannot simply be removed with a conventional patch.
  • Mac users and organizations performing sensitive cryptographic work have a newly documented hardware-level risk to assess when secret keys are handled during those operations.

Second-order effects

  • The disclosure raises the cost of security assurance for chip vendors: prior CPU side-channel research has shown that mitigation choices can affect product performance as well as security posture.
  • Buyers of Macs for security-sensitive workloads may place greater weight on operational mitigations and key-handling practices, rather than treating hardware-backed cryptographic operations as a complete boundary.

Third-order effects

  • If repeated side-channel findings persist across chip generations, processor security will be judged increasingly on how well architectures contain information leakage under real workloads, not only on whether flaws can receive software updates.
  • The resulting design trade-off is likely to become more explicit: stronger isolation may require accepting some efficiency cost, while performance-first designs can leave more residual hardware risk.

The trend: This is one instance of a wider shift in which microarchitectural performance techniques create security exposures that are difficult to fully remediate after chips ship.

Discussion

  • @arstechnica@mastodon.social @arstechnica@mastodon.social on mastodon
    Hackers can extract secret encryption keys from Apple's Mac chips  —  Fixing newly discovered side channel will likely take a major toll on performance.  —  https://arstechnica.com/...  [image]
  • @ngorby@mastodon.social Nate Gorby on mastodon
    @Techmeme great.
  • @mhoye@mastodon.social @mhoye@mastodon.social on mastodon
    A lot of people are cutting out out the “when executing cryptographic operations” part of the phrase “could drastically degrade M-series performance when executing cryptographic operations”, and glossing over the parts where it says “The researchers don't yet know what kind of pe…
  • @benlovejoy @benlovejoy on x
    No way to fix in current chips, and workarounds would involve a major performance hit - but likely not a huge concern in terms of real-world exploits ...
  • @sweis Steve Weis on x
    New GoFetch side-channel attack can leak keys from Apple M1 CPUs via Data Memory-Dependent Prefetchers (DMPs): https://gofetch.fail/
  • @danielgenkin Daniel Genkin on x
    Ever wondered what happens when side-channel resistant code meets a fancy prefetcher? Checkout our paper breaking constant time crypto on Apple CPUs. https://gofetch.fail/ Joint work with Boru Chen, @YingchenWang96, @PradyumnaShome, Chris Fletcher, @dkohlbre, @ricpacca
  • @matthew_d_green Matthew Green on x
    GoFetch: Breaking Constant-Time Cryptographic Implementations Using Data Memory-Dependent Prefetchers https://gofetch.fail/
  • r/cybersecurity r on reddit
    Unpatchable vulnerability in Apple chip leaks secret encryption keys
  • r/hardware r on reddit
    Unpatchable vulnerability in Apple chip leaks secret encryption keys
  • r/mac r on reddit
    Unpatchable vulnerability in Apple M1 - M3 chips leaks secret encryption keys
  • r/technology r on reddit
    Unpatchable Vulnerability in Apple Chip Leaks Secret Encryption Keys
  • r/MacOS r on reddit
    Unpatchable vulnerability in Apple chip leaks secret encryption keys
  • r/apple r on reddit
    Unpatchable vulnerability in Apple chip leaks secret encryption keys