logoalt Hacker News

mikewarotyesterday at 9:32 PM3 repliesview on HN

It's my long standing opinion[1] that we shouldn't accept any RAM that can be subject to random bit flips. Most of the mitigations are just security through obscurity.

[1] https://news.ycombinator.com/item?id=33860477


Replies

inigyouyesterday at 10:03 PM

My computer with a lot of ECC DDR5 sometimes catches several bitflips in a day. I know this because they are reported to dmesg and sometimes I look at dmesg.

Intel decided long ago that you would need to pay more to not be subject to random bitflips. So it's an AMD system.

e2leyesterday at 9:41 PM

I was shocked to learn that around 10% of Firefox crashes are caused by bit flips.

https://news.ycombinator.com/item?id=47252971

show 1 reply
Retr0idyesterday at 9:43 PM

Intel MEE addressed this (https://eprint.iacr.org/2016/204.pdf), by treating DRAM as entirely untrusted (assuming an attacker with arbitrary physical read/write capabilities), but then they discontinued it.

Regarding your linked comment:

> If we had properly tested and validated RAM, RowHammer wouldn't work, ever.

While it's exacerbated by physical defects and tight timings, it's really a fundamental problem with how DRAM works. It's frankly a miracle it works in the first place.

show 2 replies