Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jrtc27
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
jrtc27
5y ago
CHERI is orthogonal to virtual memory, and the two complement each other. You still want virtual memory so you can do the usual paging tricks, copy-on-write, sharing of read-only pages, and so on. Plus the fact that there is a single page t
32.
▲
by
jrtc27
5y ago
Similarly if you really want mass market adoption then you need a Windows port, otherwise most consumer PCs will remain without it, and for mobile adoption you want an iOS port (though Android does at least contribute a sizeable chunk). Por
33.
▲
by
jrtc27
5y ago
The C startup code (for statically-linked binaries) and run-time linker (for dynamically-linked binaries) carve up initial capabilities provided by the kernel into capabilities that cover the various global variables and function pointers n
34.
▲
by
jrtc27
5y ago
The simple answer is that it actually works for real-world software, is microarchitecturally feasible and flexible, and architecturally enforces non-forgeability (which is crucial allowing in-address-space compartmentalisation of distrustin
35.
▲
by
jrtc27
5y ago
Not really, because it gets traded off with the increased memory pressure due to the larger pointer size, and it'd likely be workload dependent. It's not something we've explored to date beyond hypothesising that it could be
36.
▲
by
jrtc27
5y ago
I don't see why it implies that. "Arm releases experimental DDR5-enabled $NAME board" wouldn't make it sound like DDR5 is only for Arm, so why would "Arm releases experimental CHERI-enabled Morello board"?
37.
▲
by
jrtc27
5y ago
Windows is likely a big task for the same reasons as SMAP ( https://github.com/microsoft/MSRC-Security-Research/blob/mas... ). XNU should be comparable to FreeBSD, which CheriBSD is a fork of, as both use Mach&
38.
▲
by
jrtc27
5y ago
Software doesn't need to "adopt the instructions", it just needs to be recompiled in the same way as you compile it for a new architecture (CHERI is effectively like the 32-to-64-bit transition in that sense). Yes, having cap
39.
▲
by
jrtc27
5y ago
We do have formal proofs of various security properties at the architectural level that consider the entire architecture with all its complexities and warts. Speculative execution is of course a concern (and is an active area of research fo
40.
▲
by
jrtc27
5y ago
We also have a CHERI-RISC-V specification ( https://www.cl.cam.ac.uk/techreports/UCAM-CL-TR-951.pdf ), with support in CHERI LLVM, CHERI QEMU and CheriBSD, plus three open-source FPGA implementations ( https://
41.
▲
by
jrtc27
5y ago
Our work is based on FreeBSD as its tight integration makes it much easier to manage forking in a research setting, compared with the umpteen different repositories you need to fork and keep in sync to build a Linux distribution. Arm have a
42.
▲
by
jrtc27
5y ago
Nobody's claiming it's "hack-proof", that would be foolish, just that it removes certain classes of vulnerabilities that are the majority of CVEs for code written in memory-unsafe languages, thereby reducing the attack s
43.
▲
by
jrtc27
5y ago
"ARM has developed a prototype architecture based on the Cortex-A core" isn't quite right. Armv8-A (well, Armv8.2-A in this case) is the architecture, Cortex-A is a family of implementations of that architecture. And the More
44.
▲
by
jrtc27
5y ago
You can allocate memory in another process on Unix too: use ptrace to make the other process call malloc (use PTRACE_SETREGS to set PC to malloc and the first argument register to the number of bytes, then intercept the return). GDB will us
45.
▲
by
jrtc27
5y ago
The graph is deceptive; it's a semi-log plot, so the linearity is really exponential.
46.
▲
by
jrtc27
5y ago
Most C and C++ code is perfectly happy with fat pointers provided you take care in how you implement them, especially around (u)intptr_t. For CHERI we see a very tiny % of LoC that need changing; e.g. http://www.capabilitieslimit
47.
▲
by
jrtc27
6y ago
CHERI ( http://cheri-cpu.org ) provides a spatially-safe C and C++, and also heap temporal safety (specifically it prevents use-after-reallocation, which is the actual vulnerability, since use-after-free doesn't matter if fre