logoalt Hacker News

Spaghettifying DRAM

115 pointsby matt_dtoday at 2:17 PM27 commentsview on HN

Comments

MattSteelbladetoday at 2:52 PM

I cannot wait for the accompanying Black Hat talk. Christopher Domas is one of my absolute favorite all-time hackers. He does such a fantastic job of explaining his work. Some of my favorite talks of his:

- Psychological Warfare in Reverse Engineering https://www.youtube.com/watch?v=HlUe0TUHOIc

- The MoVfuscator https://www.youtube.com/watch?v=R7EEoWg6Ekk

- Hardware Backdoors in redacted x86 https://www.youtube.com/watch?v=jmTwlEh8L7g

show 2 replies
FabHKtoday at 3:34 PM

Could someone ELI5 please? Context, achievement, scope, consequences?

ipdashctoday at 3:30 PM

I really hate to be that guy, but man, as someone who was and is a big Christopher Domas fan (and is way dumber than him, I mean, this stuff is seriously over my head)... it's been really disappointing to see him LLM'ing all the READMEs recently. They used to be a joy to read through, but now the Claudeisms made it such a slog I could barely get through a few paragraphs. I'm glad he's using the new tools to get even more cool stuff done, but I wish he'd have gone for a human writeup at the end.

dzdttoday at 2:55 PM

So on an affected system, ring 0 root has access to pretty much everything that was hidden in negative ring territory. The page is pretty quiet about what other processor families might be similar beyond this specific AMD16h (an older AMD low-power family)?

show 2 replies
devttyeutoday at 3:08 PM

The big question is whether this can break out of KVM and whether it can be microrode patched / patched in any other way.

And whether it's really real in the first place.

show 1 reply
fulafeltoday at 3:02 PM

Fascinating. So what is the DCT swizzling functionality designed for in the hardware originally?

show 1 reply
aecsockettoday at 2:53 PM

Holy shit, Christopher Domas is back. I remember watching his Defcon talks on x86 shenanigans[^1][^2] and being amazed at what he's been able to discover. Then he got whisked away by Intel and now drops this. I'm excited.

[^1]: https://www.youtube.com/watch?v=XH0F9r0siTI

[^2]: https://www.youtube.com/watch?v=jmTwlEh8L7g

show 1 reply
mschuster91today at 2:52 PM

The researcher behind this is obviously highly knowledgeable in reverse engineering CPUs to the tune it reminds me of the dwarves digging in Moria...

But why on earth do they have to use AI to write their writeups?!

show 2 replies
UltraSanetoday at 3:09 PM

Opus refuses to discuss this at all. Make of that what you will.

show 1 reply
Retr0idtoday at 2:50 PM

Holy crap. This is like a software-reachable version of the dynamic memory aliasing hardware attack demonstrated by https://batteringram.eu/

decafbadtoday at 3:14 PM

Is there any word Americans won't use as a verb.

show 4 replies
gmueckltoday at 3:36 PM

So this was onlz tested on AMD Jaguar CPUs, which are more than 10 years old? It would be good to know how many of the derived attacks can be ported to newer CPUs and whether the controller configuration is now locked down during boot.

Security has advanced a lot in those 10 years, so is it too much to wonder whether this has been quietly addressed already?