4 ms·
The kernel owns the page tables. It can always find another way in.
by bluepeter 7mo ago
The kernel owns the page tables. It can always find another way in.
- mschuster91 7mo ago> The kernel owns the page tables. not entirely, IOMMU is a thing, that is IIRC how Amazon and other hyperscalers can promise you virtual machines whose memory cannot be touched even in the case the host is compromised (and, by extension, also if the feds arrive to v& your server).
- ronsor 7mo agoIf your threat model is being v& by feds, maybe you should keep your server at home behind Tor.
- iberator 7mo agoHosting tor outbound server at home is stupid idea. Your home is gonna be raided by Police and you will wait months or year to get your shit back and then if nothing, gonna be charged for having pirated windows and Photoshop lol real story
- r_lee 7mo agolmao please tell more
- mschuster91 7mo agoNot even two years ago, see https://www.golem.de/news/nach-hausdurchsuchung-deutscher-tor-node-betreiber-kapituliert-2409-188913.html https://www.golem.de/news/nach-hausdurchsuchung-deutscher-to... And it's not just a one off occurrence either. Tor exit node operators getting v& has been a thing for decades: https://www.heise.de/news/Anonymisierungsserver-bei-Razzia-beschlagnahmt-160475.html https://www.heise.de/news/Anonymisierungsserver-bei-Razzia-b...
- mschuster91 7mo agoThese days, every American's threat model should include being v& by the feds, and here in Germany, the situation isn't much better, you can get v& for saying the Minister of Interior is a dick [1]. Yes, this was later on ruled unconstitutional, but it doesn't change the facts, and, worse, Germany doesn't have a "fruit of the forbidden tree" rule. [1] https://www.spiegel.de/panorama/justiz/hamburg-wohnungsdurchsuchung-wegen-pimmelgate-war-unrechtmaessig-a-de489269-6589-453f-896f-56e728128cea https://www.spiegel.de/panorama/justiz/hamburg-wohnungsdurch...
- matheusmoreira 7mo agoProper OPSEC dictates that the server be located as far away from home as possible, ideally in a location with zero ties to your person.
- gruez 7mo ago>how Amazon and other hyperscalers can promise you virtual machines whose memory cannot be touched even in the case the host is compromised (and, by extension, also if the feds arrive to v& your server). Even if we take those promises at face value, it practically doesn't mean much because every server still needs to handle reboots, which is when they can inject their evil code.
- Borealid 7mo agoMK-TME allows having memory encrypted at run time, and the platform TPM signs an attestation saying the memory was not altered. Malicious code can't be injected at boot without breaking that TPM.
- fc417fc802 7mo agoSubject to the huge caveat that the attacker does not have physical access. https://tee.fail/ https://tee.fail/
- deleted 7mo ago[deleted]
- Borealid 7mo agoAn interesting implementation flaw, but not a conceptual problem with the design.
- fc417fc802 7mo agoWell, it kind of is actually. The previous iteration of the design didn't have that vulnerability but it was slower because managing IVs within the given constraints adds an additional layer of complexity. This is the pragmatic compromise so to speak. Does it count as a conceptual problem when technical challenges without an acceptable solution block your goal?
- matheusmoreira 7mo agoThis is excellent. The ability to trick remote servers into believing our computers are "trusted" despite the fact we are in control will be a key capability in the future. We need stuff like this to maintain control over our computers.
- vlovich123 7mo agoBut the point here is that userspace can use this to bypass kernel protections that would otherwise prevent it from mutating R^X pages for example, not that the kernel can bypass its own.
- im3w1l 7mo agoThose protections are mainly about preventing well intentioned people from accidentally shooting themselves in the foot though, right? So it's not really a big deal that there is a way around it.
- jcalvinowens 7mo agoNo, page table write access allows arbitrary memory access because I can map any PFN I want. It's certainly a vector to execute arbitrary code in ring 0.
- vlovich123 7mo agoIt’s a huge deal. It’s a trivial gadget for building a larger exploit chain
- pjmlp 7mo agoNot really, of the security measures on Windows, is exactly to control how kernel can access secure process memory, as possible mitigation to attacks by rogue drivers. Naturally it is the kind of stuff that requires Windows 11 vlatest with the nice Pluton security CPU, as part of CoPilot+ PCs design.