3 ms·
If you read the comments to the referenced article, someone had a rowhammer problem even with ECC memory. ECC does indeed reduce the chance of a memory error a
by codinghorror 11y ago
If you read the comments to the referenced article, someone had a rowhammer problem even with ECC memory. ECC does indeed reduce the chance of a memory error a lot, but the chance is far from zero (at scale of hundreds/thousands of servers), even with ECC. Another paradox about ECC, it's not a guarantee, so you still need to build systems that can tolerate / mitigate statistically rare memory error states.
This commenter seemed quite credible to me, here's where it starts:
http://discourse.codinghorror.com/t/to-ecc-or-not-to-ecc/3771/9?u=codinghorror http://discourse.codinghorror.com/t/to-ecc-or-not-to-ecc/377...
> Yep, these are what we had -- uncorrectable errors with ECC memory caused by row hammer. Luckily there are mitigations. Sandy Bridge allows you to double...
- Dylan16807 11y agoRowhammer might get through eventually, but it will blow the corrected error count through the roof on the way there. The job of ECC is to prevent transient failures and to warn you about less-transient failures. It's not a paradox that it can't paper over things that are actually broken.
- mikeash 11y agoUncorrectable errors with ECC memory caused by row hammer is just ECC working as designed. The scary thing about rowhammer isn't just the potential a fault, it's the potential for a security vulnerability. Yeah, a DOS attack isn't nice either, but it's a million times less worse than a privilege escalation caused by memory corruption. For rowhammer to be even the same magnitude of problem with ECC memory would require not an uncorrectable error, but an error that gets past the error detection mechanism entirely and produces data either seen as correct or correctable, but which is not the original data.