logoalt Hacker News

anyfoo12/10/20243 repliesview on HN

Is that still the case? IOMMUs have been a thing for a very long time, and nowadays you don’t trust random devices anymore. Certainly a Thunderbolt port (which is PCIe-via-string) does not want to expose memory unrestricted, and while you might be tempted to think that a built-in PCIe card could be under more lax policy because it’s considered “physical access”, you don’t actually want the driver code for that card to be a wide open attack surface for the rest of the system.


Replies

KeplerBoy12/10/2024

This might also be a good time to lock down the uefi settings on one's machine to make sure someone with physical access can't just disable iommu.

lmz12/10/2024

If you bought this for cheating I guess you'd disable the IOMMU unless the game refused to run without one.

show 1 reply