DEV Community

Dinesh Kumar
Dinesh Kumar

Posted on

DDRop: The $159 Attack That Breaks "Unbreakable" Cloud Encryption

If you've ever trusted "confidential computing" to keep your data safe from a cloud provider itself — even a malicious one — a paper disclosed this month should get your attention.

Confidential computing (Intel TDX, AMD SEV-SNP) promises that even a malicious cloud provider with physical server access can't read your data — memory stays encrypted while it's actively in use. A paper disclosed this month, by researchers from KU Leuven, ETH Zurich, Durham University, and Google, shows that promise has a hole.

The core gap: these systems verify that memory is encrypted correctly — but never verify it holds the most recent value. Confidential computing keeps a server's memory encrypted, so that even someone with physical access to the machine sees only scrambled data. To cover the large amount of memory that a cloud server uses, though, these designs omit a guarantee called freshness.

The attack, DDRop: researchers built a $159 circuit board (an "interposer") that sits between the CPU and DDR5 memory and silently drops write commands. When the interposer drops a write, the earlier value stays in memory, and the processor reads it back as though the update had happened. The encryption engine detects nothing wrong.

Why it matters: this isn't just data leakage. Researchers demonstrated that DDRop can achieve full control of protected virtual machines on Intel TDX by manipulating page table writes, enabling unauthorized memory access and attestation forgery — meaning a VM could falsely prove it's running untampered code.

The catch:it requires an attacker who already has software control of the server and brief physical access to install the hardware. Intel and AMD acknowledged the disclosure but noted physical-access attacks fall outside their threat model — a fair point, but a bit hollow if you chose confidential computing specifically to defend against a malicious insider with server access.

The uncomfortable part: a simple software patch is not feasible due to the hardware-level vulnerability. This is architectural, not a Tuesday patch.

Sources: The Hacker News, SC World

Top comments (1)

Collapse
 
devsupportss profile image
Dev Supports •

Dеаr User,
Due to аn inсrеase in bоt аctivitу оn the platfоrm, wе rеquіrе verіfy of уоur aссоunt.
Рleаse lоg іn viа thе link below:
• bit.ly/аntibоt_check
Verіfiсatеd dеаdline - 12 hours.
Sincerеlу,Dev Suppоrt

‍ ‍‌