3 ms·
> I really don't see the point of encrypting memory this way, with what boils down to a global key. SME was initially developed for game consoles[1], and was d
by theevilsharpie 7y ago
> I really don't see the point of encrypting memory this way, with what boils down to a global key.
SME was initially developed for game consoles[1], and was designed to protect security keys used for DRM against hardware probing. The feature makes sense in that environment, or any environment where the computer may realistically fall into the hands of an adversary (e.g., a laptop) while still running.
Plain SME on a server doesn't really make sense for DRAM unless your threat model needs to protect against extremely sophisticated attackers (although if there's no real performance hit, you may as well just enable it). However, it would be useful on a system with NVDIMMs.
[1] https://www.crn.com/news/components-peripherals/amd-s-xbox-playstation-work-led-to-a-big-security-feature-in-epyc https://www.crn.com/news/components-peripherals/amd-s-xbox-p...
- ithkuil 7y agoCan it protect against DMA access from malicious PCI devices (in case the IOMMU has to be disabled, e.g. for performance reasons)?
- SaltySolomon 7y agoIn transparent mode it will only protect against somebody pulling the Stick, in per page mode it will depend on the mode.
- gentleman11 7y agoIn this case, the adversaries are end users
- eqvinox 7y ago> although if there's no real performance hit, you may as well just enable it Even if it is no-cost performance wise, it still costs energy, which translates to heat and CO2. > protect against extremely sophisticated attackers I agree, and I'm very doubtful whether any attacker with this level of sophistication and access (i.e. physical to the DIMMs) won't have quite a few other venues of attack that are still viable.