4 ms·
Windows has a proposed memory encryption option along with memory compression. Both Intel and AMD are working on embedding this into their CPUs. However, the
by RachelF 2y ago
Windows has a proposed memory encryption option along with memory compression.
Both Intel and AMD are working on embedding this into their CPUs.
However, the target use appears to be servers with multiple VMs, not laptops.
- p_ing 2y agoIntel has this via their Total Memory Encryption feature today. Yes, geared towards VMs in the Windows ecosystem. https://techcommunity.microsoft.com/blog/windowsosplatform/multi-key-total-memory-encryption-on-windows-11-22h2/3683043 https://techcommunity.microsoft.com/blog/windowsosplatform/m... Memory compression has been around for ages, at least since Windows 10 RTM. All major operating systems have implemented this feature -- it has no relation to security, though.
- jeroenhd 2y agoMicrosoft is moving more and more to virtualisation based security, including the ability to run “enclaves” for protecting specific pieces of software: https://learn.microsoft.com/en-us/windows/win32/trusted-execution/vbs-enclaves https://learn.microsoft.com/en-us/windows/win32/trusted-exec.... I wouldn't be surprised if they'll soon leverage encrypted “VMs” as a means of storing secrets like these. All we need is wide general hardware availability on consumer platforms. That said, previous side-channel attacks on CPUs have shown it possible to attack encrypted memory (https://www.usenix.org/conference/usenixsecurity21/presentation/li-mengyuan https://www.usenix.org/conference/usenixsecurity21/presentat...), targetting the cache as the CPU decrypts memory for normal operation. While it'll stop memory dumps from being effective, encrypted RAM won't be the end of dumping keys from memory, especially for patient or highly-skilled attackers.