13 ms·
Google says Rowhammer attacks are gaining range as RAM is getting denser
- CobaltFire 5y agoArticle title is slightly misleading: by smaller they mean process size, increasing the range of the rowhammer attacks logically due to decreased distance between memory cells even though the physics limited distance is the same.
- campuscodi 5y agoI'm the author of the article. With all due respect, but I will have to push back on your categorization as 'slightly misleading' here. Your explanation effectively explains the headline and is also what Google researchers said. How is the headline misleading?
- ma2rten 5y agoWhen I initially read the headline I thought for a second that it meant storage capacity is getting smaller. But then I realized that that doesn't make sense and it's referring to process size.
- cortesoft 5y agoNot sure how you could have read it that way... storage capacity is clearly not getting smaller.
- manquer 5y agoI had similar thoughts as the parent, then your point came to my mind, next thing I thought was perhaps not storage capacity but maybe smaller form factor of the stick itself. Clearly I was wrong, but confusion can happen with just saying "smaller", many meanings are there for that word.
- manquer 5y agoI don't think it is misleading entirely, however my first reaction was you meant smaller in storage capacity or physical size of stick this interpretation is not uncommon and can cause some confusion
- singlow 5y agoDefinitely not misleading. Possibly easy to misunderstand? It did take me a second to realize what was meant.
- hughw 5y agoNot intentionally misleading, of course. But I too first misinterpreted "RAM is getting smaller" as RAM that has smaller storage, which is counter to experience. But that's the size dimension I confront in everyday life, not the physical dimensions of the chip. I knew I must not be getting it, but I didn't think of the physical size until I read the article.
- dnautics 5y agoSlightly confusing is better verbiage. I had to think for a sec (I have had cache memory on the mind, which is "smaller" than main memory).
- comboy 5y agoI also read it that way and the paper does not use that phrase. I'm not saying intentionally misleading, but clearly some people were mislead.
- CobaltFire 5y agoMisleading may have been the wrong word, though I will say I qualified it with slightly. The changed title is much more informative.
- mhh__ 5y agoAs opposed to what other interpretation of the word small?
- a1369209993 5y agoSmall RAM: memory with (relatively) few bytes of storage.
- a1369209993 5y ago"Rowhammer attacks are gaining range as RAM is getting denser"?
- dang 5y agoOk, let's try that above. Thanks!
- karmicthreat 5y agoIs there any evidence of Rawhammer being used in a successful attack in the wild?
- babypuncher 5y agoAccording to the article, no. What I want to know is if this works on ECC memory. I'm guessing not, which makes the "vulnerability" even more of a non-issue in mission-critical applications that likely moved to ECC a while ago.
- mhh__ 5y agoApparently it does but I haven't tested it myself
- campuscodi 5y agoYes, Rowhammer can bypass ECC. Forgot to include this in the article, mainly because there's so much Rowhammer research. See here: https://www.vusec.net/projects/eccploit/ https://www.vusec.net/projects/eccploit/
- CalChris 5y agoCan Rowhammer bypass ECC and not be detected by an hw_event_mc_err_type? I don't think so. Why would someone have ECC without a sufficiently sophisticated driver?
- chmod775 5y ago> Can Rowhammer bypass ECC and not be detected by an hw_event_mc_err_type? Afaik, yes it can (unless you're counting HW_EVENT_ERR_CORRECTED). They specifically try to get 1 or 3 bit flips, never 2. See here: https://www.vusec.net/projects/eccploit/ https://www.vusec.net/projects/eccploit/ (yes, that's the same link)
- deleted 5y ago[deleted]
- Tempest1981 5y ago32 more comments here: https://news.ycombinator.com/item?id=27278540 https://news.ycombinator.com/item?id=27278540
- notriddle 5y agoIn other words, blame Intel for trying to pass off ECC as a "Enterprise Feature" instead of the basic necessity that it is.
- hypertele-Xii 5y agoECC is vulnerable to Rowhammer.
- nwah1 5y agoEqually vulnerable?
- notriddle 5y agoI saw this article linked later. https://www.vusec.net/projects/eccploit/ https://www.vusec.net/projects/eccploit/ It's interesting! It seems fixable, based on information later on in the article ("Can I get DDR3 DIMMs that are Rowhammer-free?"), and ECC only seems to be part of a solution, and not a complete solution. But you're still right, and I was still wrong: ECC alone isn't good enough.
- nullc 5y agoMuch less so.
- r00fus 5y agoThe same way that masks don't prevent COVID.
- th0ma5 5y agoRight in statistically mostly it does / they do.
- kortilla 5y agoNo, statistically it’s almost useless to prevent yourself from getting COVID. It’s mainly about reducing your ability to spread it. That’s why people get mad when you don’t wear a mask even if you “don’t care about getting covid”.
- salmo 5y agoI'm just amused that the article ends with the quote: "the challenge is substantial and the ramifications are industry-wide." Heheh. RAMifications.
- charlesmunger7 5y agoHow do I delete someone else's comment?
- goldenkey 5y agoWhile hovering over the comment, press Alt+F4 on your keyboard.
- deleted 5y ago[deleted]
- charlesmunger7 5y ago/s ...
- xwdv 5y agoIn chrome you can open up the developer tools and select the element in the source code and then just delete it.
- userbinator 5y agoBut while there are no known cases where Rowhammer attacks have been used in the real world Not on purpose but I'm sure that either it or phenomenon like it are the causes of a lot of odd "glitchy" behaviour that people encounter, because systems are run so close to their limits that there are bound to be cases when they surpass the limits. I remember many years ago discovering that a system which passed the CPU and memory stress tests of the time 100% (ran many days), but would very reliably corrupt a particular .zip file's contents upon extraction; and no other that I could see. Turning down the FSB by 1MHz(!) was enough to make it stable again. But I remain convinced that Rowhammer is a fundamental defect and all RAM which is susceptible to it should be recalled and replaced. It really says something about the industry when they've managed to convince memory testing tools to treat RH tests as "optional" and "not a real concern, most RAM will show errors" when the discovery first came to light. 26 years ago, Intel offered to recall and replace processors that couldn't divide, after an initial period of reluctance, but only once the bad publicity started. Can RAM manufacturers be coerced into doing the same, and perhaps even go back to pre-Rowhammer process sizes? Sacrificing correctness should never be an option. (This post made from a 10+-year-old machine containing RAM that is perfectly free of Rowhammer.)
- dannyw 5y agoECC Ram would mitigate some these impacts at least. But yes, it's ridiculous. Some memory sticks I buy get corrupted bits at rated speeds for my memory heavy workloads. Crucial (micron) would always accept the warranty claim, but Corsair has tried rejecting multiple claims saying their memory is designed for gaming. Now I decided to finally pay the xeon tax and go ecc memory. Yes, I know AM4 had "ecc support", but even on asrock motherboards it doesn't necessarily work.
- marcan_42 5y agoThe problem isn't RowHammer, the problem is lack of ECC. This is mostly Intel's fault, as they cripple their consumer CPU lines to disable ECC for market segmentation purposes. The entire premise that we can store tens of gigabytes of information reliably in tiny silicon capacitors without any error detection or correction whatsoever is ludicrous. Every other storage technology uses advanced error correction - NAND Flash, HDDs, optical media, etc. We've been doing this for decades. Even floppies at least had error detection (checksums). All high speed transmission protocols also do error detection and re-transmission, except HDMI (because I guess nobody cares about the odd corrupted pixel). Same for anything going over radio. Once you have ECC, your error rate margin goes up by many orders of magnitude. Worst case these attacks turn into a DoS as ECC fails to correct a badly corrupted word, and most of the time it will just work. Plus you can detect attack attempts as the memory controller will report increased error rates. It's not possible to design modern RAM that is perfectly reliable. That's just physics. We know how to solve this problem. We just aren't doing it because Intel thinks consumers don't deserve reliable RAM. The only other option is doing ECC on-chip in the RAM itself, and that has other efficiency trade-offs which probably make it not worth it, at least not with DDR style interfaces (it might've made sense in an FB-DIMM style world where the memory controller is in the RAM)
- dec0dedab0de 5y agoSo it sounds like security related flags need to be more than a single bit, and should probably be stored in different variables
- hedora 5y agoI imagine the silent downvotes are because that’s trying to solve the problem at the wrong layer. For your suggestion to work, you’d need to also duplicate the logic that checks the redundant bits, etc, etc. If you really want to do this, you end up doing what satellites do to deal with cosmic rays: Ship three identical computers. If state diverges, majority rules. See page 9 (Radiation-Effects Mitigation and Hardness) for an FPGA example: https://www.xilinx.com/support/documentation/white_papers/wp523-xqrku060.pdf https://www.xilinx.com/support/documentation/white_papers/wp...
- dschuetz 5y agoJust roll out ECC everywhere. It's not like the circuit density is going to go down again.
- LumenQ4 5y agoThough ECC is a must in DDR5 spec. We still need a physical version of ASLR to mitigate this. Ideally, we can make Rowhammer even not practical for Denial of Service. For example, running a full-speed attack for an hour only has a 0.01% chance to flip a bit.
- formerly_proven 5y agoThat's on-die error correction, DDR5 does not require ECC on the bus.
- mirker 5y agoWhat is the typical range of mean time to attack? Seconds? Is it fair to model the attack as random coin flips (i.e., following a geometric distribution)?
- cabbageoverload 5y ago3