@jonmasters made a good point that the lack of communication between SW and HW is a cause of the security problem. Understanding why the decision was made is probably a good idea, rather than assuming incompetence or idiocy. 2/N
Something like ECC with a random seed (to make the syndromes unpredictable to an attacker) and a strong enough code should be enough to at least detect (if not correct) any targeted attacks before they can succeed in sneaking in a change that somehow passes ECC.
-
-
Random per thread? Per VM? Per what? Also look at Intel’s memory encryption.
-
Per boot is fine. Once you detect an attack you have corrupted memory and there is only so much you can do that isn't panic the system. It's a DoS but not a pwn. Memory encryption helps for the same reason, as long as it's system-wide and pervasive.
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.