7 ms·
Spaghettifying DRAM
- Retr0id 2mo agoHoly crap. This is like a software-reachable version of the dynamic memory aliasing hardware attack demonstrated by https://batteringram.eu/ https://batteringram.eu/
- pocksuppet 2mo agoOh that's a clever attack. The RAM bus was often thought of as off-limits because of the speed and signal integrity requirements. They bypassed those.
- mschuster91 2mo agoThe researcher behind this is obviously highly knowledgeable in reverse engineering CPUs to the tune it reminds me of the dwarves digging in Moria... But why on earth do they have to use AI to write their writeups?!
- russdill 2mo agoSeriously. Got tired of reading the same idea over and over reworded endlessly.
- dcrazy 2mo agoI got suspicious but decided it wasn’t AI. The “Foo is the bar.” sentence construct is coherent with the overall “through the looking glass” tenor.
- jchw 2mo agoNah, it's not just that, literally all the stuff they've posted this year is obvious LLM writing, none of the stuff from previous years is. To get this close to LLM writing style without actually using an LLM, you would pretty much have to be purposefully trying. But I have a new favorite way of demonstrating this: https://github.com/search?q=owner%3Axoreaxeaxeax+load-bearing&type=code https://github.com/search?q=owner%3Axoreaxeaxeax+load-bearin... Guess how many of these are from before 2025.
- menaerus 2mo agoLike, who cares? In today's present, I wouldn't bother writing the article myself neither besides giving the instructions and auditing the output. Substance is what matters
- pocksuppet 2mo agoDid you test the substance? Did it work? AI can hallucinate substance.
- CamperBob2 2mo agoIf you don't trust the author to do that, then it doesn't matter whether they used AI or not, does it?
- jchw 2mo agoWell for one thing I also trust most people I respect to not suddenly have someone else speaking on their behalf in their voice with no disclosure in most contexts where it would not be normal, yet that seems to have happened here. So while I personally do still trust and even respect the author, I can't help but empathize with someone who is suddenly a bit more skeptical.
- CamperBob2 2mo agoSpeaking as someone who posts a lot of stuff like this, the question isn't "Do I use AI or not?" The question is, "Do I have time to deal with writing this up for public consumption or not?" This was a relatively complicated post of the sort that we are lucky to get in any form, AI-assisted or otherwise. Does it meet my personal stylistic standards? No, it's too LLM-ish. Assuming I cared about the presentation at all -- which I don't always, but would here -- I wouldn't be able to stop myself from fixing that in the process of reviewing it. Is it the usual bucket of slop? Emphatically no.
- 2mo ago
- bananaboy 2mo agoOmg yes, I found this borderline unreadable. So dense with clever phrases that say almost nothing. I came here to this thread to see if it was just me; I'm glad it wasn't!
- MattSteelblade 2mo agoI cannot wait for the accompanying Black Hat talk. Christopher Domas is one of my absolute favorite all-time hackers. He does such a fantastic job of explaining his work. Some of my favorite talks of his: - Psychological Warfare in Reverse Engineering https://www.youtube.com/watch?v=HlUe0TUHOIc https://www.youtube.com/watch?v=HlUe0TUHOIc - The MoVfuscator https://www.youtube.com/watch?v=R7EEoWg6Ekk https://www.youtube.com/watch?v=R7EEoWg6Ekk - Hardware Backdoors in redacted x86 https://www.youtube.com/watch?v=jmTwlEh8L7g https://www.youtube.com/watch?v=jmTwlEh8L7g
- Hasz 2mo agoIf this is the same dude I am thinking of, his wife is also the CISO of Mozilla and do security research together, afair they have a whole book on x86 reverse engineering. Very cool!
- Intermernet 2mo agox86 Software Reverse‐Engineering, Cracking, and Counter‐Measures By Stephanie Domas and Christopher Domas https://onlinelibrary.wiley.com/doi/book/10.1002/9781394277131 https://onlinelibrary.wiley.com/doi/book/10.1002/97813942771...
- jambalaya8 2mo agoHis stuff is something else.
- nerdsniper 2mo agoMy introduction to his work was "The future of RE Dynamic Binary Visualization"[0] which completely blew me away. It still feels futuristic today, 13 years later. Novel UI/UX paradigms like this are slow to find widespread adoption, even when they're so clearly demonstrated to be such an ideal fit for their purpose. 0: https://www.youtube.com/watch?v=4bM3Gut1hIk&pp=ygURY2hyaXN0b3BoZXIgZG9tYXM%3D https://www.youtube.com/watch?v=4bM3Gut1hIk&pp=ygURY2hyaXN0b...
- anthk 2mo ago
- aecsocket 2mo agoHoly shit, Christopher Domas is back. I remember watching his Defcon talks on x86 shenanigans[^1][^2] and being amazed at what he's been able to discover. Then he got whisked away by Intel and now drops this. I'm excited. [^1]: https://www.youtube.com/watch?v=XH0F9r0siTI https://www.youtube.com/watch?v=XH0F9r0siTI [^2]: https://www.youtube.com/watch?v=jmTwlEh8L7g https://www.youtube.com/watch?v=jmTwlEh8L7g
- vient 2mo agoHe also released another research just a few days ago https://news.ycombinator.com/item?id=49245491 https://news.ycombinator.com/item?id=49245491
- dzdt 2mo agoSo on an affected system, ring 0 root has access to pretty much everything that was hidden in negative ring territory. The page is pretty quiet about what other processor families might be similar beyond this specific AMD16h (an older AMD low-power family)?
- embedding-shape 2mo agoAs long as you know the controller's translation registers, it's applicable? Not tested on later one's merely because the information wasn't readily available it seems. > Developed and tested on AMD Family 16h CPUs, the last generation whose datasheets document the DRAM controller's translation registers — and show that they can't be locked. 17h and beyond simply leave this information out.
- m1el 2mo agofrom the GH page: > Developed and tested on AMD Family 16h CPUs, the last generation whose datasheets document the DRAM controller's translation registers — and show that they can't be locked. 17h and beyond simply leave this information out.
- fulafel 2mo agoFascinating. So what is the DCT swizzling functionality designed for in the hardware originally?
- Retr0id 2mo agoWithout any swizzling, certain common access patterns can end up with subpar performance, for example walking the columns of a 2d array with a certain stride - if it ends up directing every access to the same bank on the same channel, the throughput is much lower than if the load was evenly distributed across multiple banks/channels. Swizzling "randomizes" bank/rank/channel distribution, which makes unlucky access patterns less likely. (Something I'd like to research is microbenchmarking different access patterns to infer the swizzle pattern and defeat physical ASLR)
- Retr0id 2mo agoLate edit: It also makes it harder to exploit rowhammer etc., if the precise swizzling method is unknown.
- devttyeu 2mo agoThe big question is whether this can break out of KVM and whether it can be microrode patched / patched in any other way. And whether it's really real in the first place.
- summa_tech 2mo agoOne hopes that a hypervisor would not expose hardware control registers directly in the first place, except ones deliberately designed for virtualization support. Otherwise, the guest is running effectively at the same privilege level as the hypervisor (that's useful sometimes, but probably not intended in most applications).
- devttyeu 2mo agoYeah, just started looking at this with my team (we run a cloud with VM instance offering on AMD so this very much caught our eye) So far seems this is about right: 1. You need platform register access, so seems can't KVM-escape with just this 2. Big question is what about breaking Confidential SEV-SNP guests from the host?
- devttyeu 2mo agoOk, on 2. and in general this exploit only works on pre-Zen AMD platforms as the repo states in not-so-clear terms. Zen changed DTC (DRAM Controller) to UMC (Unified Memory Controller), UMC is programmed at boot, and one would hope they figured that locking access to it makes sense when they were adding confidential compute support; Not clear though because there is no public documentation on it, so best we can hope for is some statement from AMD/3rd party researcher saying "this won't work on Zen because X/Y/Z"
- bri3d 2mo agoWith respect to 2), I don't think this should work architecturally even if the DRAM controller has knobs which can be accessed, because the guest's RAM should be encrypted with keys that can't be recovered in this way. It's definitely a good research topic because there are a lot of moving pieces and having this kind of primitive might weaken one of them in a useful way, but at least at the top level, you couldn't just swap one guest's DRAM bank with another and get their confidential memory contents back this way.
- UltraSane 2mo agoOpus refuses to discuss this at all. Make of that what you will.
- devttyeu 2mo agoWell, K3 has no problem, Sol is also fine-ish
- HanClinto 2mo agoLikewise -- also had zero issues going over this with Sol. Seemed to give solid advice for how to test it -- use an expendable bare-metal AMD family 16h test system w/ usual standard checks that apply. > Run `platform_check` first and do not use `SKITTER_FORCE=1` casually. Start with the read-only `dram_state` and `dram_carveouts`, then `dram_dump --dry-run`. Avoid `dram_poke` until maps have been freshly collected and calibrated. Do not bypass fingerprint checks, calibration, fencing, or verification. Claude's (apparently externally-mandated?) lobotomization continues to be concerning. :-/
- peddling-brink 2mo ago> apparently externally-mandated? You mean, completely self inflicted? "Ohhh government, guess who had the most dangerous model now... tee hehe We've been so baaaaad. Look at all these companies we accidentally hacked. Whoopsee."
- rustcleaner 2mo agoGuardrails are a product-quality smell. Boycott guardrailed models. Punish guardrailed model providers with reduced revenue and bankruptcy. "I'm sorry Dave" must become a subscription-cancelling response or the nannying will never stop!
- decafbad 2mo ago[flagged]
- ImJasonH 2mo agonah we'll verb anything
- fred256 2mo agoVerbing weirds language.
- rerdavies 2mo agoHumpty Dumpty said in rather a scornful tone, “it means just what I choose it to mean—neither more nor less.” “The question is,” said Alice, “whether you can make words mean so many different things.” “The question is,” said Humpty Dumpty, “which is to be master—that's all.” -- Alice in Wonderland
- BugsJustFindMe 2mo agohttps://en.wikipedia.org/wiki/Spaghettification https://en.wikipedia.org/wiki/Spaghettification - "The term was popularized by Stephen Hawking". Hawking was English.
- nailer 2mo ago[flagged]
- ipdashc 2mo agoI really hate to be that guy, but man, as someone who was and is a big Christopher Domas fan (and is way dumber than him, I mean, this stuff is seriously over my head)... it's been really disappointing to see him LLM'ing all the READMEs recently. They used to be a joy to read through, but now the Claudeisms made it such a slog I could barely get through a few paragraphs. I'm glad he's using the new tools to get even more cool stuff done, but I wish he'd have gone for a human writeup at the end.
- BugsJustFindMe 2mo agoI find vague gestures like this almost more annoying than the idea of someone using AI to write. > the Claudeisms This is hand-waving. Please be more specific. > made it such a slog On the flip-side, I didn't find it a slog at all. What if you're wrong?
- austinthetaco 2mo agoI'm not the person you are replying to, but the readme is very clearly written by an AI, and it sounds nothing like his older work. Sometimes it's just super clear to people something is written with AI without you getting some sort of singular "gotcha" word or indicator. It's just writing patterns that would be hard to clearly establish rules for here in an HN comment, but it's incredibly obvious when you learn to spot it.
- boxed 2mo agoI mean, it's super clear to a lot of people that it's written by LLMs EVEN WHEN IT'S NOT. You can't vibe that shit too.
- shermantanktop 2mo agoI just told my boss to remove a line in a doc because it sounded too AI-y. He then said that he had written it himself.
- 2mo ago
- FabHK 2mo agoCould someone ELI5 please? Context, achievement, scope, consequences?
- self_awareness 2mo ago[flagged]
- dmitrygr 2mo agoI got you, bro: The hardware DRAM controller maps "physical addresses" approximately to: {DRAM slot number, chip number in slot, bank number in chip, row number in bank, byte number in row} via a complex map for various irrelevant reasons. All permission checks are before this mapping. So if you change the mapping, you can access shit you should not be able to, like TPM and SMM memory. OP found a way to change the mapping.
- anyfoo 2mo agoELI actually 5: You have 10 food jars in your house. Your parents only allow you to grab food from, say, the jar on the far left, and the one next to it. Sadly, those jars only contain broccoli (ordinary OS memory) and lettuce (more ordinary OS memory). But, you find out that you can just shuffle the jars around! You do a little bit of random shuffling, until you find that you have the jars with cookies (CPU microcode) and candy (SME firmware) as the leftmost ones on the shelf. Your parents take their promise very literally, and still allow you access to the two left-most jars. Which is now cookies and candy.
- deleted 2mo ago[deleted]
- deleted 2mo ago[deleted]
- dooglius 2mo agoI don't understand the threat model being attacked here. If you had physical DRAM access you could do all of this anyway right? And I would assume that an unprivileged user would not have write access to the DRAM controller registers?
- quotemstr 2mo agoEven physical DRAM access would be thwarted by transparent total memory encryption, so this hack is still something else.
- Retr0id 2mo agoIt's not fully mitigated by encryption, you can still do a lot of damage without being able to observe plaintexts. For example, you could "rewind" a ciphertext block to an earlier value, and induce a UAF-like condition in the software it belongs to.
- rzhikharevich 2mo agoApple’s Secure Enclave has replay protection since Apple A11. Generally, I don’t see why a modern security platform wouldn’t have its own private SRAM to be used as a root of trust for encrypted blobs stored in shared DRAM.
- Retr0id 2mo agoRight, that is in addition to mere encryption.
- fulafel 2mo agoThis doesn't require physical DRAM access, it's all software. With ring-0 access, this lets you poke "even things walled off and invisible to ring-0 or the CPU itself" including things that the security processor tries hard to wall off.
- 2mo ago
- cumshitpiss 2mo ago[dead]
- quotemstr 2mo agoThis is the level of access the rightful owner of a computer should have to his own system. He should also be able to fuse away this access forever, to be fair. But out of the box, when I get a new laptop, I should be able to read and write every byte of DRAM.
- gmueckl 2mo agoOK, so this works on AMD Jaguar according to the README. That's a architecture from 2013. There's notes about Zen 3 having a different base address for the memory controller registers, but that's it. What newer CPUs does attack actually work on?
- CartwheelLinux 2mo agoThat information is intentionally left out
- gmueckl 2mo agoThen publishing it in this incomplete state is just pointless fearmongering and will just make others fill in this information within the next couple of days. And the good guys likely won't be the first ones to do that.
- tecleandor 2mo agoIt's on the second paragraph, titled "Target". > Developed and tested on AMD Family 16h CPUs, the last generation whose datasheets document the DRAM controller's translation registers
- Cthulhu_ 2mo agoWhile security by obscurity isn't recommended, in this case it sounds like it's still a huge hurdle.
- fc417fc802 2mo agoYes, a hurdle to effective security research. Something hidden only appears to have no vulnerabilities. By raising the bar on a mass market product of this sort you ensure that in the event well funded actors develop exploits in secret they won't be inadvertently discovered by the public.
- devttyeu 2mo agoZen has completely different memory controller IP (UMC), that's configured at boot by AGESA/PSP. I doubt this exploit applies to modern Zen CPUs, however AMD are the only ones who could really confirm this.
- WhiteDawn 2mo agoThis is all great to get full unfettered access to your own system, as life should be. I’m sure Xbox and PlayStation security groups are a little nervous right now though. Getting ring-0 on those machines is near impossible, but once you do then everything else becomes wide open
- ransom_rs 2mo agoSeems like this should get us a newer PS4 jailbreak?
- ammar2 2mo agoNot sure if it opens up that much on them as far as their security processors go. Modern consoles already treat DRAM as completely untrusted (an attacker could just sit on the DRAM bus and sniff/issue requests there). The Xbox One for example encrypts all the DRAM it uses after it gets out of the main CPU die. See this part of Tony Chen's presentation https://youtu.be/U7VwtOrwceo?t=956 https://youtu.be/U7VwtOrwceo?t=956 Also see this bit on the Apple Secure Enclave in the "Memory Protection Engine" section which also explains how they encrypt stuff stored in DRAM: https://support.apple.com/guide/security/the-secure-enclave-sec59b0b31ff/web https://support.apple.com/guide/security/the-secure-enclave-...
- PunchyHamster 2mo agowouldn't request after DRAM controller be unencrypted ? Would need to have different key per memory type and even then you could do some damage as realistically it won't have number of keys equal to running processes
- crote 2mo agoModern server CPUs have different memory encryption keys per VM, it's how AWS Nitro Secure Enclaves can work.
- ransom_rs 2mo agoIn the README it talks about accessing and modifying the code of the Platform Security Processor including accessing the keys, how is what is on an Xbox different?
- hn4jkltkab 2mo ago[dead]
- zahlman 2mo agoThis is only applicable if you already have root (in order to get beyond that), right? It doesn't expose new risk of local privilege escalation?
- odo1242 2mo agoYep, I believe so
- ziofill 2mo agoBut it supercharges what can be done once you get root, no?
- odo1242 2mo agoYep.
- UltraSane 2mo agoBy a LOT. It would expose the data Windows keeps isolated using virtualization based security.
- odo1242 2mo agoDoes this mean the exploit can be used in a VM to get access to the host machine?
- smaudet 2mo agoNot necessarily. A VM doesn't have a "real" DMA controller, and this exploit is specific to a family of real hardware CPUs. Its not to say that its not impressive, but its fairly isolated to a specific family of processors from 2013.
- odo1242 2mo agoOh, right. I forgot that DMA controllers are virtualized on VMs.
- Permik 2mo agoSkitter creek bath salts... Or SCBS Guess there'll be a talk called Secure Computing BullShit in the next Blackhat conf! I'll be eagerly waiting for it! :)
- pocksuppet 2mo agoThis is probably very interesting, but does it really have to be explained with a solid wall of AI slop writing?
- weinzierl 2mo agoWhen I started with computers, DRAM was understandable by a teenager: RAS, CAS, read, done. Ok, the necessary refresh was always a little pain, but still something manageable. Nowadays, I feel you need three PhD's to even bring up a micro with DRAM and don't get me started on the proprietary binary blobs necessary just for DRAM access. No wonder PSRAM is a thing. The corollary is that it shouldn't be too surprising that this gigantic attack surface provides many opportunities. (Of course that doesn't mean it is easy to find them, hat tip to Christopher Domas, just that I expect there to be many more).
- RachelF 2mo agoSo true. The levels of indirection from a pointer to an actual DRAM chip address are insane. Then there's the electrical bus: DDR5 runs so fast it need channel characterisation (sorta like the old model dial up sounds) on the lines between the controller and the DRAM. No more 5V and 0V for TTL signals there.
- skavi 2mo agois that a distinct process from DRAM training?
- namibj 2mo agoShouldn't be; at least if you count the termination setting trials that already were a thing with DDR4 as "DRAM training".
- altairprime 2mo agoTraining is the general description of the processes underlying both the DFE and the MBIST bios settings, which are usually separated into different sections; very broadly, the former (DFE) is the one most commonly thought of as DRAM Training and focuses the ‘physical’ layer training i.e. electrical characterization, while the latter (MBIST) configures how rigorously the channel’s ‘protocol’ layer training evaluates signal eyes tests over the physical transport. You can draw an analogy for comprehension purposes between DFE and 1/2.5/5/10G auto-detection logic in Ethernet, which does various circuit-level characterization; and between MBIST and f3probe, which writes data and then reads it back in various algorithmic test patterns to ensure that the electrical training produced a usable result that can carry data as specified rather than just claiming to and then crashing later on.
- ecshafer 2mo agoThis is so cool. Outside of a cool demo, and maybe some black hat type stuff, this is surely dangerous, a bad idea, and shouldn't be done in prod. But pure hacker ethos at its heart.
- raver1975 2mo agoI spaghettify my memory every time I write C code.
- anthk 2mo agoOn IntelME/AMD PSP: https://jxself.org/titanic.shtml https://jxself.org/titanic.shtml He did it well. On "security", the author loves more to own his code/adata than anything. as did the PDP10/ITS hackers.
- titularcomment 2mo agoIs ARM truly more user-friendly in this regard? And I dont see no genuine alternative than arm64
- anthk 2mo agoGIving the device tree it looks far worse.
- dezgeg 2mo agoHow so? In my experience, the peak of Device Tree days was with the final 32-bit ARM chips before move to aarch64. Back then you had U-Boot which did minimal stuff and after that the kernel had full ownership of the hardware, no management firmware layers or extra code at runtime. It's during the move to 64-bit aarch64 where things started to imitate the x86, with more and more always-on firmware and secure monitors and whatever being introduced. Nothing really to do with device tree, in fact ACPI is being pushed to the ARM too, yet again hiding more details of the hardware towards proprietary bytecode.
- wartywhoa23 2mo agoAlas, if only x86 was indeed just a single Titanic to get sunk and forgotten. Instead, it's the blueprint for all the subsequent unsinkable ships in terms of surveillance capabilities.
- nnevatie 2mo agoThis is quite excellent.
- semiquaver 2mo agoWhere did this guy come from? Suddenly I’m seeing new amazing hardware exploits from them every day! https://news.ycombinator.com/from?site=github.com/xoreaxeaxeax https://news.ycombinator.com/from?site=github.com/xoreaxeaxe...
- simianparrot 2mo ago[flagged]
- __alexander 2mo agoSo nice to see Christopher Domas posting code again.
- matheusmoreira 2mo agoSo what's inside Intel ME, AMD PSP and associaded firmwares? Don't leave us hanging here...
- wartywhoa23 2mo agoI've been waiting fervently for some kind of IntelMEgate since the day I learned about IntelME.
- randyrand 2mo agoI’m confused. Why is this remapping option exposed to userspace?
- stefanha 2mo agoIt's not. In the demo video the exploit code is a Linux kernel module, not a userspace application.
- nullc 2mo agoThis is a great starting point to go looking for PSP / SMM backdoors.
- phendrenad2 2mo agoThis requires Ring 0 already, correct? That would seriously limit its usefulness for hacks or jailbreaks.
- nwmcsween 2mo agoWould you be able to put a payload into EEPROM with this?
- webprofusion 2mo agoNeeds more emojis
- dfedbeef 2mo agoWhat a fuckin legend
- peter_d_sherman 2mo agoMy absolute favorite HN article of all time, to date! Absolutely brilliant! The vendor locked regions (on hardware that you already own!) that this could unlock (or help future security researchers to unlock, in the case of later model CPU's) has the potential to solve many auditability/transparency/defensive security/repair (cf. "Right to Repair") problems in the future. Christopher Domas has earned the right to be called a 'Legend' -- again! (For probably like what, the 3rd or 4th time now? :-)) Anyway, upvoted and favorited!
- catspajamas8837 2mo agoIm confused seeing all the negative 'he used AI in writeups'. This guy released 5 new open source projects last week, including white papers and gave 3 unique talks (2 blackhat, 1 defcon). NONE of those conferences require whitepapers or open sourcing tools, he chose to do that because he gives a shit. In an ideal world would he have used up all of his free time to write white papers by hand, sure. But instead he used AI to help him go faster (who among us can honestly say were not using in our daily lives??) As someone whos been a HUGE fan of his work for a long time let me add some positivty to this thread. I'm SOOO thankful that hes still spending his free time doing incredible research, releasing functional documented open source, and bothering to release white papers. When so many researchers I see today slap a cheeky logo on a shitty blog post and call it awesome.