3 ms·
Hmm, it seems that all the pieces aren't in place yet. If I'm understanding correctly, the exploit technique they use relies on cross-page errors (causing error
by zwegner 11y ago
Hmm, it seems that all the pieces aren't in place yet. If I'm understanding correctly, the exploit technique they use relies on cross-page errors (causing errors in one page with accesses to another page), because the page with errors needs to get freed to the operating system to potentially reuse as PTEs, while still having the ability to cause the errors. There's a line on one of the slides that says you can use timing information to get cross-page information, but I'm really not sure what that means, and how feasible it is.
In addition, they need to find a double-bit error, one that would change both the writable bit and an address bit, if a PTE was in that place in memory. They mentioned that they tested their laptop for these errors, and they're possible, but much rarer--how rare? This point was kind of just glossed over.
I'd guess that these two combined would make an exploitable error much more unlikely.
- creshal 11y ago> how rare? This point was kind of just glossed over. It varies widely between memory chips, memory controllers, and a variety of other factors. Not to mention, Rowhammer was first disclosed early last year, and many vendors started shipping BIOS updates to prevent Rowhammer on the memory controller level months ago; additionally the problem has been fixed from the start on DDR4 RAM (the bug has been known to memory vendors before, but not been deemed a security problem, so the fix wasn't applied retroactively to DDR3). So finding actually exploitable devices now is going to be difficult.
- yuhong 11y agoTo be more precise, the feature in DDR4 is called TRR and the one in DDR3 is called pTRR.
- revelation 11y agoWho has ever updated their BIOS? Unless Windows now does this silently.
- creshal 11y agoCorporate IT should hopefully have mechanisms for it in place, because those tend to fix a lot of problems… and security relevant bugs. Edit: And additionally, yes, Windows 10 can ship BIOS updates, assuming the hardware and UEFI supports it.
- TazeTSchnitzel 11y agoApple machines handle firmware updates like any other software update.
- yuhong 11y agoYea, I think they even started bundling them with Mac OS X updates now.