Log inSign up
Mark Ermolov
1,599 posts
Image
user avatar
Mark Ermolov
@_markel___
I research security of Intel platforms. I don't work for Intel
Москва, Россия
Joined September 2014
131
Following
12.1K
Followers
  • Pinned
    user avatar
    Mark Ermolov
    @_markel___
    May 19, 2020
    Finally, the casket is opened: we (+@h0t_max and @_Dmit) have extracted Intel x86 microcode! One more Intel "top secret" information gets revealed... github.com/chip-red-pill/…
    Image
    Image
  • user avatar
    Mark Ermolov
    @_markel___
    Mar 19, 2021
    Wow, we (+@h0t_max and @_Dmit) have found two undocumented x86 instructions in Intel CPUs which completely control microarchitectural state (yes, they can modify microcode)
    Image
    Image
    Image
  • user avatar
    Mark Ermolov
    @_markel___
    Aug 26, 2024
    Intel HW is too complex to be absolutely secure! After years of research we finally extracted Intel SGX Fuse Key0, AKA Root Provisioning Key. Together with FK1 or Root Sealing Key (also compromised), it represents Root of Trust for SGX. Here's the key from a genuine Intel CPU😀
    Image
    973K
  • user avatar
    Mark Ermolov
    @_markel___
    Feb 12, 2022
    The very important goal has been achieved, for the benefit of the entire information security society: we decrypted Intel XuCode!
    Image
    Image
    Image
  • user avatar
    Mark Ermolov
    @_markel___
    Sep 20, 2017
    We did it: Intel ME 11.x arbitrary code execution, #BHEU blackhat.com/eu-17/briefing…
  • user avatar
    Mark Ermolov
    @_markel___
    Oct 8, 2022
    A very bad thing happened: now, the Intel Boot Guard on the vendor's platforms can no longer be trusted... ☹️
    Image
  • user avatar
    Mark Ermolov
    @_markel___
    Aug 26, 2024
    Replying to @_markel___
    They really tried hard to protected the key: the part of ucode works perfectly but they forgot to clear the internal buffer in the core IP holding all fuses (including FK0) acquired from Fuse Controller
    Image
    59K
  • user avatar
    Mark Ermolov
    @_markel___
    Mar 5, 2020
    Intel x86 Root of Trust: loss of trust: blog.ptsecurity.com/2020/03/intelx…
  • user avatar
    Mark Ermolov
    @_markel___
    Jul 7, 2021
    Here're all the technical details of the undocumented x86 instructions which we (+@h0t_max and @_Dmit) found: github.com/chip-red-pill/…
  • user avatar
    Mark Ermolov
    @_markel___
    Jun 25, 2024
    Lack of coordination between Intel CSME security/firmware team and PCH HW team has led to a very big fail: Fuse Encryption Key has been extracted!
    Image
    54K
  • user avatar
    Mark Ermolov
    @_markel___
    Aug 26, 2024
    Replying to @_markel___
    The last step is remaining nevertheless to fully compromise Intel SGX - knowing of FK0 Fuse Encryption Key (FK0 FEK), but we hope to do it like we did for CSME...
    51K
  • user avatar
    Mark Ermolov
    @_markel___
    Mar 19, 2021
    Replying to @_markel___
    They're decoded in all modes (even in User Mode) but the ucode in MSROM throws #UD if not in Red Unlocked state. All details a little later...
  • user avatar
    Mark Ermolov
    @_markel___
    Aug 10, 2021
    I can't believe it: Intel decided to be open about the debugging capabilities of their chips. Our work definitely bears fruit: software.intel.com/content/www/us…
  • user avatar
    Mark Ermolov
    @_markel___
    May 18, 2021
    Today, we (+@h0t_max and @_Dmit) decided to publish our microcode disassembler tool for Intel Atom Goldmont core:
    Image
    GitHub - chip-red-pill/uCodeDisasm
    From github.com

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up
Advertisement
Advertisement