news.volyx.in

Blacksmith – Rowhammer bit flips on all DRAM devices today despite mitigations (comsec.ethz.ch)

662 points by buran77 · 1770 days ago · 309 comments on HN

Article summary

Researchers have demonstrated that Rowhammer bit flips can be triggered on all DRAM devices today, despite deployed mitigations, using a new approach called Blacksmith. This vulnerability allows attackers to induce bit flips in DRAM memory, which can have significant security implications. The researchers tested 40 DDR4 devices from major manufacturers and found that their Blacksmith fuzzer could trigger bit flips on all of them. This result suggests that current DRAM devices are not secure against Rowhammer attacks.

Main themes

  • Rowhammer vulnerability
  • DRAM security
  • Cloud computing risks
  • Hardware vs software security
  • Market priorities
  • Regulation and standards
  • Secure computing environments

What commenters say

  • The Rowhammer vulnerability is a hardware bug that cannot be fixed by software alone.
  • ECC memory can make Rowhammer attacks harder, but it is not a complete solution.
  • The cloud is not a secure environment for computing due to the risk of Rowhammer attacks.
  • Without safe hardware, it is almost impossible to write safe software.
  • Certifications, audits, and minimum mandated standards are necessary to ensure security, but they must be effective and well-designed.
  • The market prioritizes low costs over security, making it difficult for manufacturers to develop and sell secure products.
  • Some commenters argue that dedicated tenancy or metal configurations can mitigate the risks of Rowhammer attacks in the cloud.
  • Others believe that the problem is not just with the cloud, but with the entire computing industry, which prioritizes speed and low costs over security.