4 ms·
I agree that rowhammer needs a hardware-based defense. While ECC isn't prohibitively expensive and has negligible performance cost, keep in mind it's only a par
by server_bot 9y ago
I agree that rowhammer needs a hardware-based defense. While ECC isn't prohibitively expensive and has negligible performance cost, keep in mind it's only a parity check with a proprietary implementation. There's some multiple of bit flips that will pass the parity check and still achieve the attacker's intended result, and the exploit is definitely going to get multiple attempts - if you get pwned the malicious process might be in memory and hammering away for hours, maybe it's even dropped a registry key to make sure it auto runs next boot.
Reference: http://blog.erratasec.com/2015/03/some-notes-on-dram-rowhammer.html http://blog.erratasec.com/2015/03/some-notes-on-dram-rowhamm...
- toast0 9y agoIt's true that it is possible to flip enough bits to bypass ECC and make whatever nefarious change. However, it seems likely that first you're going to make a lot on correctable errors, which will slow down your system. Even if you don't notice that, chances are you're going to get a double bit error which will halt your system many times before you get a triple bit (or whatever) that gets the desired exploit.