| ▲ | dooglius 40 minutes ago | |
I don't understand the threat model being attacked here. If you had physical DRAM access you could do all of this anyway right? And I would assume that an unprivileged user would not have write access to the DRAM controller registers? | ||
| ▲ | fulafel 14 minutes ago | parent | next [-] | |
This doesn't require physical DRAM access, it's all software. With ring-0 access, this lets you poke "even things walled off and invisible to ring-0 or the CPU itself" including things that the security processor tries hard to wall off. | ||
| ▲ | quotemstr 34 minutes ago | parent | prev [-] | |
Even physical DRAM access would be thwarted by transparent mandatory memory encryption, so this hack is still something else. | ||