27 ms·
You're trying to catch the specific implementation of the attack rather than the general attack. Suppose they don't lie about the size of the memory, instead th
by zrm 2y ago
You're trying to catch the specific implementation of the attack rather than the general attack. Suppose they don't lie about the size of the memory, instead they find a way to mask out one of the address bits so reads from higher addresses go to lower addresses or vice versa. Which they can change in hardware at runtime after you've done whatever checks you want and which doesn't necessarily have to be the most significant bit.
- dale_glass 2y agoOh, I'm sure, but this just seems like an oddly simple exploit that seems to rely on things that almost look like they shouldn't work. Like you'd think things like address lines being shorted together, or not being connected, or such things would be simple to test for in a millisecond or two, and be a logical part of a basic test of functionality that just checks that everything seems to be wired up right.