3 ms·
It will detect (by crashing) enough to make exploitation impractical. That is the key point.
by crotchfire 3y ago
It will detect (by crashing) enough to make exploitation impractical. That is the key point.
- reliabilityguy 3y agoI would say that 60% success per trial is a good chance.
- exmadscientist 3y agoIn the process of generating one triple flip, many, many, many, many, many single and double flips will occur and will be caught. That is why ECC is still an effective defense. Attackers don't just get to go straight to their end game.
- reliabilityguy 3y ago--
- rightbyte 3y agoThat's true for encryption too.
- exmadscientist 3y agoThe ECCploit paper has extensive discussion of all the ways their work is detected, and how they even use detection to probe the correction structure. This is not a silent attack. This is a proof that ECC is a penetrable defense. Which we all know! The question is how difficult it is and how stealthily it can be done. But regardless, ECC still sounds the alarm when it's being attacked. If no one listens, there's not much ECC can do about that.
- YetAnotherNick 3y agoYou can cause any amount of single and double flip without worry. It's not a defence as the attacker can retry till ECC labels it as uncorrectable. AFAIK there is no cost in retrying.
- exmadscientist 3y agoThat's true, but none of it is silent. Corrected errors get reported and it will be obvious that something is going wrong to anyone who's paying attention.
- YetAnotherNick 3y agoReported where? There is no reporting in Ryzen CPUs.
- namibj 3y agoGot a reference? Because my Zen3 desktop has the driver loaded and information shown, just not the bitflips but that may be due to excessively early refresh configuration.
- adrian_b 3y agoNormally you should not see any bit flips, because they happen at intervals of several months or even less frequently, depending on location. Only for some old modules, e.g. 5-years old or older, the frequency of errors can increase a lot, even up to many bit flips per day, which means that the offending module must be replaced. This feature of identifying the aged modules is one of the main benefits of ECC. I have not looked again at the AMD EDAC driver, which has been updated during last year, but previously, a couple of years ago, its feature of injecting errors for testing was broken on Ryzen (because it had not been updated since Bulldozer, at that time), so the only method to verify that error reporting is working was to overclock the memory in the BIOS settings, to ensure that errors will be generated. Obviously, for the test one should boot from read-only media, to avoid the corruption of the storage in the case of excessive errors.
- namibj 2y agoI've overall looked at about 100 GB*years of edac counter on this massive, and never once there was any error. If I knew how, I'd dial down the voltage very slowly while running a rowhammer PoC to either catch it hammering or catch edac counts.