
With the map now in your possession, you can now disable Swizzle and force a read or write to normally inaccessible areas of the DRAM, since you now know where it will land. With this, you can access all the previously hidden code and data, netting you hardware-level access to do anything you want, including reading fTPM signing code and any other low-level shenanigans you can think of.
Attentive readers might be wondering why the system doesn't crash during this process since you're effectively temporarily turning the RAM into a spaghetti mess. The answer is that every time you enable and disable Swizzle, you prepare the CPU by disabling interrupts, along with a number of other measures. Even still, the machine can crash during the map-collection step, but that only needs to be done once. After you have the map, the likelihood of a crash is fairly low since you'll be targeting specific locations.
Another question might be why sending a bit to a memory location somehow messes with the CPU, and the answer is that part of OS-accessible memory is actually mapped to hardware according to the Memory-Mapped Configuration Space standard (MMCONFIG) — meaning that reads or writes to that space are directed to hardware configuration settings, not actual RAM. Edit 8/14/2026: Clarified TPM.
Follow Tom's Hardware on Google News , or add us as a preferred source , to get our latest news, analysis, & reviews in your feeds.
Bruno Ferreira is a contributing writer for Tom's Hardware. He has decades of experience with PC hardware and assorted sundries, alongside a career as a developer. He's obsessed with detail and has a tendency to ramble on the topics he loves. When not doing that, he's usually playing games, or at live music shows and festivals. ","collapsible":{"enabled":true,"maxHeight":250,"readMoreText":"Read more","readLessText":"Read less"}}), "https://slice.vanilla.futurecdn.net/13-4-25/js/authorBio.js"); } else { console.error('%c FTE ','background: #9306F9; color: #ffffff','no lazy slice hydration function available'); } Bruno Ferreira Social Links Navigation Contributor Bruno Ferreira is a contributing writer for Tom's Hardware. He has decades of experience with PC hardware and assorted sundries, alongside a career as a developer. He's obsessed with detail and has a tendency to ramble on the topics he loves. When not doing that, he's usually playing games, or at live music shows and festivals.
wakuwaku With this, you can access all the previously hidden code and data, netting you hardware-level access to do anything you want, including reading fTPM signing code and any other low-level shenanigans you can think of. And how do you propose we do that MR. Tom's AI. You do know that ftpm doesnt exist in these older AMD CPUs. Do we fuse it with newer ones using magic? Reply
drea.drechsler T wakuwaku said: And how do you propose we do that MR. Tom's AI. You do know that ftpm doesnt exist in these older AMD CPUs. Do we fuse it with newer ones using magic? I wonder if it would work the same with a dTPM. They do support those at TPM1.2 and they function to protect Bitlocker keys, albeit at a much reduced security posture. But this could be just one more tempest in a teapot since it appears you'll need both physical access to the system and, what sounds like, Admin privileges on the targeted OS volume to be able to work at the kernel level. With those it's game over no matter how you shake it. Reply
PEnns Ludicrous. In other news, a hard working hacker, more prolific than other prolific hackers, called 2Obvious, claim to have hacked into 1993 Pentiums very easily using nothing but telepathy and a can of super cold Dr. Pepper. Reply
COLGeek PEnns said: Ludicrous. In other news, a hard working hacker, more prolific than other prolific hackers, called 2Obvious, claim to have hacked into 1993 Pentiums very easily using nothing but telepathy and a can of super cold Dr. Pepper. How cold? That is probably key to the outcome. 😉 Reply
PEnns COLGeek said: How cold? That is probably key to the outcome. 😉 Liquid Nitrogen cold…..you're on to something here!! 😊 Reply
DS426 PEnns said: Ludicrous. In other news, a hard working hacker, more prolific than other prolific hackers, called 2Obvious, claim to have hacked into 1993 Pentiums very easily using nothing but telepathy and a can of super cold Dr. Pepper. Get the story right, it was MOUNTAIN DEW!!! 🤣 Reply
drea.drechsler DS426 said: Get the story right, it was MOUNTAIN DEW!!! 🤣 you're all wrong… Jolt cola. Reply
Key considerations
- Investor positioning can change fast
- Volatility remains possible near catalysts
- Macro rates and liquidity can dominate flows
Reference reading
- https://www.tomshardware.com/tech-industry/cyber-security/SPONSORED_LINK_URL
- https://www.tomshardware.com/tech-industry/cyber-security/just-one-instruction-on-amds-2015-era-cpus-gets-you-access-to-platform-security-processor-microcode-and-system-management-interface-exploit-for-15h-and-16h-chip-families-cracks-open-secret-memory-areas#main
- https://www.tomshardware.com/membership
- Universitas Gadjah Mada, Indosat and NVIDIA Open Indonesia’s First University AI Center to Develop Local AI Talent
- Just one instruction on AMD's 2015-era CPUs cracks open secret memory areas and gives full hardware-level control — exploit for 15h and 16h chip families gets y
- Class Is in Session: GeForce NOW Levels Up Linux, Chromebooks and More
- Older Raptor Lake CPUs are a ‘core part of the portfolio’ for years to come, says Intel — there’s been a ‘sudden inrush of demand’ for LGA 1700 chips due to DDR
- Alabama residents left powerless to stop massive Bitcoin mining data center despite county and town moratoriums — hole in state zoning laws lets facility throug
Informational only. No financial advice. Do your own research.