3 ms·
A properly configured IOMMU (VT-d in intel parlance) should prevent most physical ram dump attack vectors. The good news is that almost all x86 chips are shippi
by trotsky 14y ago
A properly configured IOMMU (VT-d in intel parlance) should prevent most physical ram dump attack vectors. The good news is that almost all x86 chips are shipping with one on die these days. The bad news is that support is thin - many vendors don't ship good firmware for it. Software wise support is mixed - your OS needs to manage what drivers have access to what pages. Since it's seen as primarily a virtualization technology, virtualization platforms handle it best - xen is top notch and works well out of the box. Other OS's can mostly be well configured with some patience with the notable exception of darwin (apple hardware also lacks vt-d firmware support).
If you're in a situation where you're truly concerned about your door being busted down you're almost guaranteed to be subject to a ram dump if you're vulnerable, primarily via firewire, unlocked workstations and local exploits but a myriad of less common vectors exist.
- sweis 14y agoIOMMU does not protect against non-volatile RAM or bus analyzers. Plus, "properly configured" is essential; most operating systems are not.