any details on which CPUs that worked on? /cc @lavados @yuvalyarom @anders_fogh @misc0110
-
-
-
also: "r-x"? don't you mean "rw-"?
-
I think he meant that we have a way to do read and execute with those techniques as in r-x. rwx with rowhammer.
End of conversation
New conversation -
-
-
Not too surprising: if the name of the game is speed you throw out all security checks, for privilege level as well as executable bit. I can't think of any other security checks right now but if there are any, they're also likely bypassed in speculative execution.
-
On that note, I'm beginning to wonder if one could use speculative execution to make a CPU *actually* divide by zero. Side channel being a sudden creation of a local black hole.
-
Ohhh, I'd forgotten about that one... :D
- 1 more reply
New conversation -
-
-
Pretty sure data can't be written out of the store buffer to memory until an instruction retires. Memory is global, so it would be visible to other threads (and not be speculative) if that occured.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Should systems allow dynamically-generated code & if so, what’s right mode for data/stack areas where instructions written?
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
if you haven't seen it, this seems like something too, lots of notes that need to be organised.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Do you know if that talk was recorded and will be posted somewhere? I would like to see it despite missing Shmoocon this year.
- 1 more reply
New conversation -
-
-
I'm failing to see how this is any worse than Spectre already is. At best it seems to give you more Spectre gadgets to work with.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
I suppose this would allow for an end run around OpenBSD's W^X... *sigh*
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Why is it called ShmooCon?
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Aww, man.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
anything more on this?
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Great.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.