Intel and AMD chips have a new hole: what the TONTOU attack is and why you should care
Imagine you are driving and, before reaching a curve, you already know almost for sure which way the road is going to turn. That is why you do not brake completely: you keep going at a similar pace. Your mobile or computer does something similar on the inside. The chips guess, almost all the time, what is going to happen next, in order to go faster. That trick is what has caused problems again, and this time it has been demonstrated by researchers from the Massachusetts Institute of Technology, better known as MIT.
First, the basics: why computers guess
To understand the news you need one simple idea. Inside your computer there is a chip, called a processor, which is like the brain of the machine. It does millions of calculations per second. To go faster, the chip does not wait to be sure of what is coming: it guesses and gets ahead. If it is right, it saves time. If it is wrong, it throws away the work. That is fine for speed.
The problem is that, when it is wrong, it leaves small traces of what it was thinking. And since 2018 it has been known that there is a way to read those traces to spy on data that should not be seen. That trick is called Spectre (which means “ghost” in English). New variants keep being discovered, and this is the most recent one.
What the MIT researchers have found now
Technicians from the brands have spent years putting defences in place to plug the hole. The idea is simple: clean or isolate the part of the chip that guesses, just before it is used, so that nobody can plant anything weird there. It seems like a good solution.
But researchers Daniel Trujillo and Mengjia Yan, from MIT, have discovered that this cleaning is not instantaneous. Between the moment it is cleaned and the moment the chip uses that part again, there is a very small window of time. Like when you clean a table and there is a second in which you can get it dirty again before someone uses it. The researchers have found a way to slip in right through that gap.
They have called this new trick TONTOU, and they have tested it on chips from the two big brands: Intel and AMD, across several generations of processors. On both, they managed to make it work.
What can they achieve with this?
This is not just theory. On a test computer using an AMD chip, the researchers managed to read protected system data and, in half the attempts, find the file where the computer’s administrator password is stored. In other words, they managed to demonstrate that the hole is useful for stealing sensitive information.
That sounds serious, and it is. But it has to be put in context. The attack is slow and complicated: it takes about 18 minutes to complete and needs very specific conditions. It is not something an ordinary criminal could do to your home computer so easily, like sending a trick message. Nor is it a virus that slips in on its own.
So, although the news is frightening, the experts insist that a normal family does not have to sleep in fear. The serious danger is above all in large servers, those powerful machines that many companies use and where an intruder could take advantage of the gap. That is why it is an important issue for the industry, even though for you the practical consequences today are few.
What can I do to protect myself?
The good part is that the problem is already known and is on the way to being solved. The researchers warned Intel and AMD in February, and the Linux system maintainers in March. AMD has already released a patch that largely fixes the hole, and that fix reaches your computer through a system update.
An update is like a vaccine for the computer: it corrects known weak points. So the most useful thing you can do is the usual thing, but which really works: install the updates when you are asked to, both on your mobile and your computer, and do not put them off for months. That simple gesture closes most of these doors.
The summary in three sentences
MIT researchers have found a new way to get into Intel and AMD chips, bypassing the defences put in place after the famous Spectre flaw. The attack works, but it is slow and complicated, so the real danger right now is small for the average user. The only thing you need to keep an eye on is your system updates, which is the vaccine already circulating.
This finding is being presented this same month at two important computer security conferences, Black Hat and USENIX, where experts from all over the world will share the details so the industry can keep closing traps. In the meantime, if your system is up to date, there is nothing urgent to do.






