# Gaping Security Hole in 64-Bit Vista!

**URL:** <https://boards.straightdope.com/t/gaping-security-hole-in-64-bit-vista/370394>\
**Category:** Miscellaneous and Personal Stuff I Must Share\
**Created:** [August 27, 2006, 7:44am UTC](https://boards.straightdope.com/t/gaping-security-hole-in-64-bit-vista/370394 "2006-08-27T07:44:43Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tuckerfan](https://avatars.discourse-cdn.com/v4/letter/t/eada6e/32.png) [@Tuckerfan](https://boards.straightdope.com/u/Tuckerfan)\
**Post date:** [August 27, 2006, 7:44am UTC](https://boards.straightdope.com/t/gaping-security-hole-in-64-bit-vista/370394/1 "2006-08-27T07:44:43Z")

</div>

And, boy, is it _bad!_ I’ll post a link to the site with the info in a moment, but since it’s a podcast (though you can read a transcript on the site) and the one guy sort of gets sidetracked constantly (though it’s still related info and important), I’ll give you a brief summary, then you can fetch a second set of undies so that when you check out the podcast and crap your pants, you’ll have a clean pair handy.

Here’s the deal, on the new 64 bit systems, the _hardware_ is designed so that it can have programs _outside_ the OS running. A software expert noticed this and wrote an exploit she calls “Blue Pill.” Once it’s ran on your machine (and there’s several very simple delivery systems for it) there is literally _ **NO** _ practical way for you to detect it. Because it sits between the OS and the hardware, it can totally block **all** attempts at detection, including such things as checking clock cycles. Microsoft says that they’re going to develop something to prevent this from happening, **but** they’re going to have to work at such a deep level (namely blocking boot sector viruses) that there’s serious doubt they’ll be able to pull it off. (Is anyone surprised?)

You can check it out [here.](http://www.grc.com/securitynow.htm) It’s episode #54 entitled _Blue Pill_ and you can chose to listen to it in a variety of formats or read the transcripts.

---

<div class="post-metadata">

**Author:** ![Quartz](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/quartz/32/267_2.png) [@Quartz](https://boards.straightdope.com/u/Quartz)\
**Post date:** [August 27, 2006, 8:34am UTC](https://boards.straightdope.com/t/gaping-security-hole-in-64-bit-vista/370394/2 "2006-08-27T08:34:43Z")

</div>

See also [here](http://sunbeltblog.blogspot.com/2006/08/little-blue-pill-big-black-hat.html) and [here](http://blogs.zdnet.com/Ou/index.php?p=297).

[Here’s the author’s blog entry](http://theinvisiblethings.blogspot.com/2006/07/blue-pill-hype.html).

---

<div class="post-metadata">

**Author:** ![Sage\_Rat](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/sage_rat/32/399_2.png) [@Sage\_Rat](https://boards.straightdope.com/u/Sage_Rat)\
**Post date:** [August 27, 2006, 9:09am UTC](https://boards.straightdope.com/t/gaping-security-hole-in-64-bit-vista/370394/3 "2006-08-27T09:09:26Z")

</div>

It should be pointed out that (outside of the Xbox), Microsoft doesn’t do hardware, so it’s rather hard to say that this is a Visa-64 issue. Linux 64 would probably be equally insecure on the same hardware.

> [@](#):
>
> Although some articles and blogs have given the impression that it’s based on a vulnerability in the Vista operating system, it’s actually based on AMD’s SVM Pacifica virtualization technology (and Rutkowska herself has been very clear that the exploit is not based on any flaw in Vista)

---

<div class="post-metadata">

**Author:** ![Mindfield](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mindfield/32/19759_2.png) [@Mindfield](https://boards.straightdope.com/u/Mindfield)\
**Post date:** [August 27, 2006, 2:37pm UTC](https://boards.straightdope.com/t/gaping-security-hole-in-64-bit-vista/370394/4 "2006-08-27T14:37:38Z")

</div>

Indeed. According to the articles, this is currently an exploit of the AMD 64 Hypervisor virtualization technology. At the moment, it requires that the victim be running an AMD 64 processor (though it is also possible on the Intel 64-bit architeture’s own virtualization technology) and a 64-bit operating system. Furthermore it isn’t presently possible to conceal the Blue Pill (“level 2”) from the OS until either IOMMU or

---

<div class="post-metadata">

**Author:** ![Mindfield](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mindfield/32/19759_2.png) [@Mindfield](https://boards.straightdope.com/u/Mindfield)\
**Post date:** [August 27, 2006, 2:38pm UTC](https://boards.straightdope.com/t/gaping-security-hole-in-64-bit-vista/370394/5 "2006-08-27T14:38:51Z")

</div>

Dammit, premature-post mousing accident.

Anyway, it won’t be possible for a Blue Pill-type rootkit to completely conceal itself from the OS until either AMD’s IOMMU or Intel’s

---

<div class="post-metadata">

**Author:** ![Mindfield](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mindfield/32/19759_2.png) [@Mindfield](https://boards.straightdope.com/u/Mindfield)\
**Post date:** [August 27, 2006, 2:42pm UTC](https://boards.straightdope.com/t/gaping-security-hole-in-64-bit-vista/370394/6 "2006-08-27T14:42:41Z")

</div>

Did you know that there’s a particular key combination that posts your damn message for you?

Well there is.

So yeah:

…or Intel’s VT-d I/O virtualization is implemented, which is currently is not and won’t be 'til next year sometime. I wouldn’t start panicking yet, as there’s still plenty of time to work out ways to detect and prevent the installation of virtualized rootkits. And since this exploit was discovered by a security researcher instead of a hacker, there’s a bit of a head start advantage.

---

<div class="post-metadata">

**Author:** ![Diceman](https://avatars.discourse-cdn.com/v4/letter/d/22d042/32.png) [@Diceman](https://boards.straightdope.com/u/Diceman)\
**Post date:** [August 27, 2006, 6:50pm UTC](https://boards.straightdope.com/t/gaping-security-hole-in-64-bit-vista/370394/7 "2006-08-27T18:50:25Z")

</div>

I was planning on building a new computer next year. After reading this, I’m going to make sure that I can disable any virtualization technology that my processor uses. Or better yet, choose one without this feature. I have no interest in running multiple OS’s anyway.

---

<div class="post-metadata">

**Author:** ![Tuckerfan](https://avatars.discourse-cdn.com/v4/letter/t/eada6e/32.png) [@Tuckerfan](https://boards.straightdope.com/u/Tuckerfan)\
**Post date:** [August 27, 2006, 9:49pm UTC](https://boards.straightdope.com/t/gaping-security-hole-in-64-bit-vista/370394/8 "2006-08-27T21:49:04Z")

</div>

> [@Sage Rat](#):
>
> It should be pointed out that (outside of the Xbox), Microsoft doesn’t do hardware, so it’s rather hard to say that this is a Visa-64 issue. Linux 64 would probably be equally insecure on the same hardware.

True, however, given that it often takes Microsoft a _very_ long time to issue patches for even simple security matters, I’d be willing to bet that the Linux community will have the problem solved before Microsoft will (and I’d also imagine that since Apple’s now using Intel chips, they could fall prey as well, but again, Apple’s patch cycle seems to operate faster than Microsoft’s).
