Project Zero: Exploiting the DRAM rowhammer bug to gain kernel privileges
googleprojectzero.blogspot.com
Project Zero: Exploiting the DRAM rowhammer bug to gain kernel privileges
1–10 of 103 posts
Re: Project Zero: Exploiting the DRAM rowhammer bug to gain kernel privileges
#2Re: Project Zero: Exploiting the DRAM rowhammer bug to gain kernel privileges
#3You know, this makes me wonder. If a car manufacturer or a toy company made a product that was found to be unsafe, there would be a recall. If hardware manufacturers make a product that is insecure, will there be a recall? Unfortunately, I suspect that this is a case where the law hasn't caught up with technology.
[0] http://www.pcadvisor.co.uk/news/pc-components/3259061/intel-...
Re: Project Zero: Exploiting the DRAM rowhammer bug to gain kernel privileges
#4Re: Project Zero: Exploiting the DRAM rowhammer bug to gain kernel privileges
#5You know, this makes me wonder. If a car manufacturer or a toy company made a product that was found to be unsafe, there would be a recall. If hardware manufacturers make a product that is insecure, will there be a recall? Unfortunately, I suspect that this is a case where the law hasn't caught up with technology.
Good luck trying that though!
Re: Project Zero: Exploiting the DRAM rowhammer bug to gain kernel privileges
#6Does anyone know if Macbooks are known to be affected?
Re: Project Zero: Exploiting the DRAM rowhammer bug to gain kernel privileges
#7You know, this makes me wonder. If a car manufacturer or a toy company made a product that was found to be unsafe, there would be a recall. If hardware manufacturers make a product that is insecure, will there be a recall? Unfortunately, I suspect that this is a case where the law hasn't caught up with technology.
Re: Project Zero: Exploiting the DRAM rowhammer bug to gain kernel privileges
#8Does anyone know if Macbooks are known to be affected?
here's the test: https://github.com/google/rowhammer-test
Re: Project Zero: Exploiting the DRAM rowhammer bug to gain kernel privileges
#9You know, this makes me wonder. If a car manufacturer or a toy company made a product that was found to be unsafe, there would be a recall. If hardware manufacturers make a product that is insecure, will there be a recall? Unfortunately, I suspect that this is a case where the law hasn't caught up with technology.
For that matter, the "no"s on that table really only prove that the exact stick they tested with the exact memory locations they tested did not exhibit detectable bit flips. It doesn't prove that those sticks are "safe", let alone that the product line they come from is safe.
So, basically, what's vulnerable? To a first approximation, everything. What would happen if we tried to recall every bit of DRAM produced in the past X years (where X is also unknown)? Well... you'd bankrupt the industry is what you'd do. That's not a very useful outcome.
In fact this sort of thing happens all the time. New safety tech is developed for cars all the time, but you can't go back and sue the auto companies for not including it before it was invented or the need for it was discovered [1]. This seems more like that problem than an actual problem of negligence or "defects" being produced.
[1]: Well... more or less. I know of cases where this was successfully done, though they tend to get overturned on appeal. Run with me here.