Remix.run Logo
dooglius 40 minutes ago

I don't understand the threat model being attacked here. If you had physical DRAM access you could do all of this anyway right? And I would assume that an unprivileged user would not have write access to the DRAM controller registers?

fulafel 14 minutes ago | parent | next [-]

This doesn't require physical DRAM access, it's all software.

With ring-0 access, this lets you poke "even things walled off and invisible to ring-0 or the CPU itself" including things that the security processor tries hard to wall off.

quotemstr 34 minutes ago | parent | prev [-]

Even physical DRAM access would be thwarted by transparent mandatory memory encryption, so this hack is still something else.