7 ms·
It seems like the root problem here, as in lots of security problems, is an assumption made early on is no longer valid (e.g. "this application only runs on our
by seldo 13y ago
It seems like the root problem here, as in lots of security problems, is an assumption made early on is no longer valid (e.g. "this application only runs on our LAN, so no need to protect against malicious actors"). In this case, PCI was originally an internal technology -- adding a new PCI device involved opening the case and plugging in a new card. Pluggable PCIe devices changed that assumption, so things that were previously pretty safe (trusting a new piece of hardware physically installed into the box) became unsafe (trusting a random device plugged into the box).
- AaronFriel 13y agoIt's not even that - well, maybe a little bit that, but all pieces of hardware with independent processors could theoretically own your machine. (Even, theoretically, pieces of hardware that attach to your machine that only emulate simple state machines could hijack your CPU and make a "weird machine".) The problem here is fundamentally one of performance - PCIe and other devices cannot function efficiently without direct memory access. The only reason FireWire was capable of the speeds it originally was, was because of DMA. USB didn't have DMA (and still doesn't? I think..) and so for shuttling large amounts of uncompressed data into the address space of a consuming application, it was incredibly inefficient to involve the CPU. PCI-Express and other buses followed a similar route - DMA is vastly superior to every other way of transferring data. Theoretically an I/O memory management unit with virtualization support could protect your machine, but I don't know if any OSes and hardware combinations actually use that to protect the machine.
- nine_k 13y agoThe problem is not in DMA. The problem is that DMA is allowed across memory protection, without authorization and without user consent. I suppose it made sense when Macs and PCs ran single-user OSes on hardware that lacked memory protection. Keeping the default behavior from that day is not wise for, well, last decade or so. (Fresh OSX seems to have changed accordingly, as the tool's page mentions.)
- yuliyp 13y agoYou mean the problem with Direct Memory Access is that it's Direct? Memory protection, authorization checks, and user consent are all implemented by the CPU knowing which pieces of memory are what. If you use DMA you're just writing to and reading from specific locations on the RAM chips, irrespective of what the CPU wants you to do. RAM chips don't have ACLs; They'll do whatever requests hit their pins.
- wmf 13y agoThe IOMMU is basically ACLs for RAM, but OSes don't use it as much as they could (possibly because Intel disables it on random SKUs).
- Dylan16807 13y agoIt's really easy to have direct access to a single range of memory and no access outside of that range. It's also really easy to have somewhat more complicated schemes. There is nothing inherently insecure about DMA. It's just shoddy protocols and/or protocols used in unexpected ways.
- reeses 13y agoThis is another of those "people did it 100 years ago and now we have to reinvent it" things. The Mark I would never have had this problem.
- beagle3 13y agoThere's a handshake that's done with the PCIe device; It doesn't cost anything to keep the address/data lines off until the handshake is complete, and require that the user approve the handshake. True, this will not stop an e.g. accepted external drive from DMAing - but it will stop a randomly plugged thing from doing so. Not having this level is worse than Windows' of old tendency to autorun anything called "autorun.inf" on a media - because autorun was still subject to user privileges whereas the PCIe "autorun" is not.
- lgeek 13y agoI don't see the concept of DMA as unsafe. I'm not that familiar with x86, but it seems that random devices can set up DMA transfers. Why? I guess there were performance considerations, but in that case an IOMMU needs to be used. On the systems I've worked on, only the CPU can set up DMA transactions (which includes transfer length, source and destination), which should prevent trivial attacks.
- nly 13y agoOne advantage of bus mastering, at least in theory, is that you can do peer-to-peer transfers without going through main system memory. In practice, I don't think this works out too well for really heavy workloads... both NVIDIA SLI and AMD Crossfire require their own interconnects, presumably because of limited bus bandwidth. Remember the days when you had a separate MPEG-2 decoder card that externally proxied VGA from your graphics card?
- deleted 13y ago[deleted]
- pacaro 13y agoMicrosoft, at least, was thinking about this and trying to mitigate as early as 2003 [1], Attacks over FireWire or SCSI were part of the threat model that the Palladium team was concerned about. [1] http://www.google.com/patents/US7975117 http://www.google.com/patents/US7975117