Spaghettifying DRAM

(github.com)

66 points | by matt_d 46 minutes ago

6 comments

  • fulafel 1 minute ago
    Fascinating. So what is the scrambling functionality for in the hardware originally?
  • MattSteelblade 10 minutes ago
    I cannot wait for the accompanying Black Hat talk. Christopher Domas is one of my absolute favorite all-time hackers. He does such a fantastic job of explaining his work. Some of my favorite talks of his:

    - Psychological Warfare in Reverse Engineering https://www.youtube.com/watch?v=HlUe0TUHOIc

    - The MoVfuscator https://www.youtube.com/watch?v=R7EEoWg6Ekk

    - Hardware Backdoors in redacted x86 https://www.youtube.com/watch?v=jmTwlEh8L7g

    • Hasz 6 minutes ago
      If this is the same dude I am thinking of, his wife is also the CISO of Mozilla and do security research together, afair they have a whole book on x86 reverse engineering.

      Very cool!

  • dzdt 8 minutes ago
    So on an affected system, ring 0 root has access to pretty much everything that was hidden in negative ring territory. The page is pretty quiet about what other processor families might be similar beyond this specific AMD16h (an older AMD low-power family)?
  • aecsocket 10 minutes ago
    Holy shit, Christopher Domas is back. I remember watching his Defcon talks on x86 shenanigans[^1][^2] and being amazed at what he's been able to discover. Then he got whisked away by Intel and now drops this. I'm excited.

    [^1]: https://www.youtube.com/watch?v=XH0F9r0siTI

    [^2]: https://www.youtube.com/watch?v=jmTwlEh8L7g

  • mschuster91 11 minutes ago
    The researcher behind this is obviously highly knowledgeable in reverse engineering CPUs to the tune it reminds me of the dwarves digging in Moria...

    But why on earth do they have to use AI to write their writeups?!

  • Retr0id 13 minutes ago
    Holy crap. This is like a software-reachable version of the dynamic memory aliasing hardware attack demonstrated by https://batteringram.eu/