Arm releases experimental CHERI-enabled Morello board
lightbluetouchpaper.org
Arm releases experimental CHERI-enabled Morello board
1–10 of 84 posts
Re: Arm releases experimental CHERI-enabled Morello board
#2Re: Arm releases experimental CHERI-enabled Morello board
#3Re: Arm releases experimental CHERI-enabled Morello board
#4Re: Arm releases experimental CHERI-enabled Morello board
#5I wager it will be hacked in under a year.
Re: Arm releases experimental CHERI-enabled Morello board
#6I wager it will be hacked in under a year.
Nobody's claiming it's "hack-proof", that would be foolish, just that it removes certain classes of vulnerabilities that are the majority of CVEs for code written in memory-unsafe languages, thereby reducing the attack surface. Independent analysis by both Microsoft and Google has shown that's around 70% of vulnerabilities, which still leaves around 30%, but is a big step forward.
Re: Arm releases experimental CHERI-enabled Morello board
#7I wager it will be hacked in under a year.
In a sense the entire aim of this is for it to be 'hacked' to further improve the security architecture.
Re: Arm releases experimental CHERI-enabled Morello board
#8Earlier quoted context omitted.
Nobody's claiming it's "hack-proof", that would be foolish, just that it removes certain classes of vulnerabilities that are the majority of CVEs for code written in memory-unsafe languages, thereby reducing the attack surface. Independent analysis by both Microsoft and Google has shown that's around 70% of vulnerabilities, which still leaves around 30%, but is a big step forward.
Not OP, but that's not how I interpreted their comment. I interepreted it as the 70% they hope to have fixed will end up having edge cases not yet considered, and the protections will end up weaker than desired. No-one designed a processor to be susceptable to spectre and meltdown, once something moves into production there is significantly more incentive to investigate and find these flaws.
Re: Arm releases experimental CHERI-enabled Morello board
#9Earlier quoted context omitted.
Nobody's claiming it's "hack-proof", that would be foolish, just that it removes certain classes of vulnerabilities that are the majority of CVEs for code written in memory-unsafe languages, thereby reducing the attack surface. Independent analysis by both Microsoft and Google has shown that's around 70% of vulnerabilities, which still leaves around 30%, but is a big step forward.
Not OP, but that's not how I interpreted their comment. I interepreted it as the 70% they hope to have fixed will end up having edge cases not yet considered, and the protections will end up weaker than desired. No-one designed a processor to be susceptable to spectre and meltdown, once something moves into production there is significantly more incentive to investigate and find these flaws.
Either they aren't interesting for hackers, or they actually did a good job with hardware memory tagging.
Re: Arm releases experimental CHERI-enabled Morello board
#10I wager it will be hacked in under a year.