- Psychological Warfare in Reverse Engineering https://www.youtube.com/watch?v=HlUe0TUHOIc
- The MoVfuscator https://www.youtube.com/watch?v=R7EEoWg6Ekk
- Hardware Backdoors in redacted x86 https://www.youtube.com/watch?v=jmTwlEh8L7g
0: https://www.youtube.com/watch?v=4bM3Gut1hIk&pp=ygURY2hyaXN0b...
Very cool!
He did a fantastic job of explaining his work.
https://www.youtube.com/watch?v=iOq8O_phwbA
He looks so different.
Ok, the necessary refresh was always a little pain, but still something manageable.
Nowadays, I feel you need three PhD's to even bring up a micro with DRAM and don't get me started on the proprietary binary blobs necessary just for DRAM access. No wonder PSRAM is a thing.
The corollary is that it shouldn't be too surprising that this gigantic attack surface provides many opportunities. (Of course that doesn't mean it is easy to find them, hat tip to Christopher Domas, just that I expect there to be many more).
Then there's the electrical bus: DDR5 runs so fast it need channel characterisation (sorta like the old model dial up sounds) on the lines between the controller and the DRAM. No more 5V and 0V for TTL signals there.
I’m sure Xbox and PlayStation security groups are a little nervous right now though. Getting ring-0 on those machines is near impossible, but once you do then everything else becomes wide open
The Xbox One for example encrypts all the DRAM it uses after it gets out of the main CPU die. See this part of Tony Chen's presentation https://youtu.be/U7VwtOrwceo?t=956
Also see this bit on the Apple Secure Enclave in the "Memory Protection Engine" section which also explains how they encrypt stuff stored in DRAM: https://support.apple.com/guide/security/the-secure-enclave-...
You would have first break the firmware or locks before an attack like this on a modern CPU
But why on earth do they have to use AI to write their writeups?!
In an ideal world would he have used up all of his free time to write white papers by hand, sure. But instead he used AI to help him go faster (who among us can honestly say were not using in our daily lives??)
As someone whos been a HUGE fan of his work for a long time let me add some positivty to this thread. I'm SOOO thankful that hes still spending his free time doing incredible research, releasing functional documented open source, and bothering to release white papers. When so many researchers I see today slap a cheeky logo on a shitty blog post and call it awesome.
And whether it's really real in the first place.
Absolutely brilliant!
The vendor locked regions (on hardware that you already own!) that this could unlock (or help future security researchers to unlock, in the case of later model CPU's) has the potential to solve many auditability/transparency/defensive security/repair (cf. "Right to Repair") problems in the future.
Christopher Domas has earned the right to be called a 'Legend' -- again!
(For probably like what, the 3rd or 4th time now? :-))
Anyway, upvoted and favorited!
https://news.ycombinator.com/from?site=github.com/xoreaxeaxe...
He should also be able to fuse away this access forever, to be fair. But out of the box, when I get a new laptop, I should be able to read and write every byte of DRAM.
https://jxself.org/titanic.shtml
He did it well. On "security", the author loves more to own his code/adata than anything. as did the PDP10/ITS hackers.