Lina received a $150k bounty for this exploit.
Sounds extremely low for this kind of vulnerability of a $2.7T company that prides itself for its privacy accomplishments.
How do you know that?
71–80 of 140 posts
Lina received a $150k bounty for this exploit.
OS development, security, shader programming, computer architecture, etc.
The code is clean and has plenty of comments explaining what is happening at each step.
And for the ones do not know, Asahi Lina is the same person who made it possible to run GPU-enabled Linux on Apple Silicon, among with other contributors.
Lina received a $150k bounty for this exploit.
Sounds extremely low for this kind of vulnerability of a $2.7T company that prides itself for its privacy accomplishments.
A level only fit for products where [3]: "some confidence in correct operation is required, but the threats to security are not viewed as serious" which is one level lower than "demonstrating resistance to penetration attackers with a basic attack potential" [4]. Which is four full levels below "demonstrating resistance to penetration attackers with a moderate attack potential" [5].
Apple has never once, over multiple decades of failed attempts, demonstrated "resistance to penetration attackers with a moderate attack potential" for any product. It should be no surprise that the systems, processes, and people who lack the knowledge, ability, technology, and experience to make a system resistant to moderate attackers, despite nearly unlimited resources, have the security of their systems completely defeated by moderate attacks like small groups of skilled researchers. Apple positively, absolutely, 100%, certifies they can not. Though, it would be nice if their marketing were restricted to what their engineering can prove.
[1] https://support.apple.com/guide/certifications/macos-securit...
[2] https://support.apple.com/library/APPLE/APPLECARE_ALLGEOS/CE...
[3] https://www.commoncriteriaportal.org/files/ccfiles/CC2022PAR... Page 14
[4] https://www.commoncriteriaportal.org/files/ccfiles/CC2022PAR... Page 16
[5] https://www.commoncriteriaportal.org/files/ccfiles/CC2022PAR... Page 20
Earlier quoted context omitted.
Sounds extremely low for this kind of vulnerability of a $2.7T company that prides itself for its privacy accomplishments.
>Sounds extremely low for this kind of vulnerability How do you know that?
From code comments, what I understood (most likely in an incorrect way) is: - Use Metal shader code to make process page table accessible to shaders via page protection layer bug exploited using return oriented programming (ROP) - Use Metal shader code to acquire read/write access to physical memory - Use Metal shaders to access the kernel page table - Deals with ASLR to find the kernel base address - Obtains process…
You’re pretty much correct. GPUs are a very interesting attack vector. Especially as more computation is being pushed to GPUs, and they’re not always well isolated.
[flagged]
The HN rules say > Please don't complain about tangential annoyances—e.g. article or website formats, name collisions, or back-button breakage. They're too common to be interesting. Given that many are praising the formatting, I don't see how the rule applies. I'd like to point out that the slides have source available and use the reveal js slides framework, but I'm not sure if this would be considered as breaking th…
Lina received a $150k bounty for this exploit.
Once again, my respect for the work of the Asahi team and especially Linas GPU related efforts grows further. Great to see that she was officially recognized[0] and received a bounty for her efforts. [0] https://support.apple.com/en-md/HT213488