Live data from Hacker News

Calling NSA to find your encryption key after a few bits were flipped (2010)

astroengineer.wordpress.com

121–125 of 125 posts

Re: Calling NSA to find your encryption key after a few bits were flipped (2010)

#121
post #88

Earlier quoted context omitted.

Oddly apropos anecdote to your pun: About 15 years ago, while working on Windows at Microsoft, a test machine sitting at my desk hit a kernel panic (BSOD). As was standard working on the test team, the machine was already setup for kernel debugging, and so I set out to debug it a bit in order to file a decent bug report. Hours later, I couldn't make sense of it (I wasn't super experienced at this point). A few of the…

Ray complained in 2005 that Microsoft sees lots of weirdo crash reports from computers with overclocked CPUs https://devblogs.microsoft.com/oldnewthing/20050412-47/?p=35...

Awwww, that Windows Me must have been overclocked out-of-the-box considering the amount of BSOD :D

Re: Calling NSA to find your encryption key after a few bits were flipped (2010)

#122
post #109

Can a cosmic rays flip 0’s to 1’s and visa versa, or just in in one direction? Edit: I am thinking of memory chips

I think only 1 to 0, as the cosmic ray cause electrons to "discharge" hence lowering the voltage, assuming that 1 is a little bit higher voltage than 0. But far from an expert in electronics and physics :)

Quoting the NASA incident report:

Updated May 17, 2010 at 5:00 PT.

One flip of a bit in the memory of an onboard computer appears to have caused the change in the science data pattern returning from Voyager 2, engineers at NASA’s Jet Propulsion Laboratory said Monday, May 17. A value in a single memory location was changed from a 0 to a 1.

On May 12, engineers received a full memory readout from the flight data system computer, which formats the data to send back to Earth. They isolated the one bit in the memory that had changed, and they recreated the effect on a computer at JPL. They found the effect agrees with data coming down from the spacecraft. They are planning to reset the bit to its normal state on Wednesday, May 19.

Re: Calling NSA to find your encryption key after a few bits were flipped (2010)

#123

Earlier quoted context omitted.

I gather DDR5 will have ECC as standard du to the extreme density of memory that will bitflip a lot more than usual. Yay fo r consumers.

DDR5 supports on-chip ECC but the extra parity bits we typically associate as "ECC" are still as optional as ever, motherboard manufacturers will still not bother to route those signals anyway, and Intel will still demand you give up overclocking and pay more for Xeon in order to use ECC sticks.

I did some reading up on this just now. You are of course right in that ECC on-chip will only handle bitflips inside the chip. To ensure the integrity of signals between the memory and the processor traditional ECC will still be required. On DDR5 it will be necessary to have 4 parity chips whereas with DDR4, you only need 2, so true ECC capable memories will be considerably expensive.

Re: Calling NSA to find your encryption key after a few bits were flipped (2010)

#124
post #117

Earlier quoted context omitted.

I do, because a picture of the criminal might be worth more than $10,000, or you might have to call an ambulance and your life is worth something

>I do, because a picture of the criminal might be worth more than $10,000, or you might have to call an ambulance and your life is worth something He had the chance to have a good solution and decided it's not worth it, that's the difference. >and your life is worth something Restart your phone.

> Restart your phone.

Alright, next time my 80 year old grandoa is having a heart attack I am sure he will have time to wait for android to boot, then input the encryption key

Thats why i still keep a dumbass analogue phone wired to the socket - our industry is full of wankers and cant be trusted

Re: Calling NSA to find your encryption key after a few bits were flipped (2010)

#125
post #117

Earlier quoted context omitted.

>I do, because a picture of the criminal might be worth more than $10,000, or you might have to call an ambulance and your life is worth something He had the chance to have a good solution and decided it's not worth it, that's the difference. >and your life is worth something Restart your phone.

> Restart your phone. Alright, next time my 80 year old grandoa is having a heart attack I am sure he will have time to wait for android to boot, then input the encryption key Thats why i still keep a dumbass analogue phone wired to the socket - our industry is full of wankers and cant be trusted

>Alright, next time my 80 year old grandoa is having a heart attack I am sure he will have time to wait for android to boot, then input the encryption key

Let's go an buy her a Mainframe and three redundant inet connections and power-lines, but don't try to sue intel because of your own stupidity to rely on a cellphone...alone!

If you trust your life to a cellphone.....your problem.

And just for your information...your cellphone is not a server nor reliable...keep that in mind, go climbing in mountains and you see the massive difference from your iphone to a rugged satellite-phone (with buttons), but even then, never ever trust a single device.

Post reply on HN