4 ms·
That does look like it: https://www.intel.com/content/www/us/en/developer/articles/news/runtime-encryption-of-memory-with-intel-tme-mk.html https://www.intel.c
by throwaway914 3y ago
That does look like it:
https://www.intel.com/content/www/us/en/developer/articles/news/runtime-encryption-of-memory-with-intel-tme-mk.html https://www.intel.com/content/www/us/en/developer/articles/n...
Looks like AMD has an equivalent:
https://www.tomshardware.com/news/intel-mktme-amd-memory-encryption,39467.html https://www.tomshardware.com/news/intel-mktme-amd-memory-enc...
I wish there were a sort of checklist that prints out in dmesg saying "Your RAM is encrypted: (check) Your machine has these mitigations against cold-boot attacks: ...some list here... (check, check, check)"
In some contexts, I love how far we've come with secure boot, attestation, speculative execution mitigations, etc. but it's very difficult for the average Linux user to understand what they should expect for hardware security, and then work toward enabling all of it.
I love what Gnome did in the last year in Settings -> Device Security:
https://www.phoronix.com/news/Ubuntu-No-GNOME-Device-Security https://www.phoronix.com/news/Ubuntu-No-GNOME-Device-Securit...
There's a detailed list here of what it's looking for:
https://forums.debian.net/viewtopic.php?t=152705 https://forums.debian.net/viewtopic.php?t=152705
Not a fan of all the bound-to-Intel technologies. I wish the concept of what's being secured were identified, then made available in dmesg or through some /sys or /proc interface.
- adrian_b 3y agoAMD Epyc servers have offered encrypted memory for many years. Intel is only now catching up.
- matja 3y agoI have an AMD CPU and I get in my kernel logs during boot: [ 0.338594] Memory Encryption Features active: AMD SME
- throwaway914 3y agoI mean like a checklist of security capabilities that are enabled/disabled, all grouped together in dmesg. That is cool though, it does help