Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
apropos man
Sep 5, 2016

You get a hundred and forty one thousand years and you're out in eight!
Wtf is that supposed to mean? I'd be better off with Win10 on it? Chortle.

Adbot
ADBOT LOVES YOU

deimos
Nov 30, 2006

Forget it man this bat is whack, it's got poobrain!

apropos man posted:

Would it be possible to have two verions of the kernel: one for Vee-Emming and one for plain desktop/laptop use? I don't wanna lose up to 30% performance.

This is probably a bad idea, but fuckit: hit post.

This affects non VMs as well, theoretically a Javascript payload could install a rootkit. That's how hosed this is.

The problem is that this is a ring-crossing bug, that's what makes it deadly. Rings for reference.

deimos fucked around with this message at 17:47 on Jan 3, 2018

Wiggly Wayne DDS
Sep 11, 2010



deimos posted:

This affects non VMs as well, theoretically a Javascript payload could install a rootkit. That's how hosed this is.
that's not theoretical and the same threat model from rowhammer applies. here's a recent presentation on a js-based attack to defeat aslr: https://www.youtube.com/watch?v=ewe3-mUku94

rowhammer was publicised in 2014, you should have been in a panic since then if this affects you

Space Gopher
Jul 31, 2006

BLITHERING IDIOT AND HARDCORE DURIAN APOLOGIST. LET ME TELL YOU WHY THIS SHIT DON'T STINK EVEN THOUGH WE ALL KNOW IT DOES BECAUSE I'M SUPER CULTURED.

apropos man posted:

Would it be possible to have two verions of the kernel: one for Vee-Emming and one for plain desktop/laptop use? I don't wanna lose up to 30% performance.

This is probably a bad idea, but fuckit: hit post.

This is a bad idea.

It looks like VM escapes (or guest-to-host/cross-guess reads, or whatever) are one possibility for this attack. They're getting a lot of attention because so many public-facing services are isolated with VMs. But that doesn't mean they're the only bad thing that can happen. Unless your single-tenant no-VM desktop is air gapped, physically secured so only you can use it, and runs only carefully audited software, you need to be able to isolate unprivileged code from kernel space.

apropos man posted:

Wtf is that supposed to mean? I'd be better off with Win10 on it? Chortle.

Clearly your choice of OS is superior to the washed masses. Chortle.

BlankSystemDaemon
Mar 13, 2009



In the good tradition of PoC||STFU, here's some PoC:

"no page faults required, massaging everything in/out-of the right cache seems to be the crux".

CLAM DOWN
Feb 13, 2007




Wiggly Wayne DDS posted:

rowhammer was publicised in 2014, you should have been in a panic since then if this affects you

Honestly, I'm basically perpetually in a panic in this industry

Thermopyle
Jul 1, 2003

...the stupid are cocksure while the intelligent are full of doubt. —Bertrand Russell

Intel releases next generation without bug:

Now with 30% more performance!

Alereon
Feb 6, 2004

Dehumanize yourself and face to Trumpshed
College Slice

CLAM DOWN posted:

Thread title
Clever but too long :(

BlankSystemDaemon
Mar 13, 2009



They usually say that detailed commit messages are a good thing, but maybe not in this case.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

I don’t think there’s incremental damage to be done, given the guy tweeting about a PoC.

BlankSystemDaemon
Mar 13, 2009



Subjunctive posted:

I don’t think there’s incremental damage to be done, given the guy tweeting about a PoC.
A PoC without code disclosure is one thing, these are commits to the Linux kernel, so the code itself is public - I'd think that's a big bigger of an issue?

Trabisnikof
Dec 24, 2005

D. Ebdrup posted:

A PoC without code disclosure is one thing, these are commits to the Linux kernel, so the code itself is public - I'd think that's a big bigger of an issue?

I believe the embargo on the committed code isn't over yet. But yeah, the cat is out of the bag.

Klyith
Aug 3, 2007

GBS Pledge Week

deimos posted:

This affects non VMs as well, theoretically a Javascript payload could install a rootkit. That's how hosed this is.

are you positive? the writing about this made it seem to me like the bug can only read kernel memory. and that to turn it into an attack you'd need to actually use that information -- either as a target for a second vulnerability, or just stealing the leaked data itself. which is why VMs are brought up all the time.

but if I'm totally misunderstanding it and you can use it to write to arbitrary memory as well then count me in on the holy poo poo bandwagon.

The Fool
Oct 16, 2003


The exploit is read only.

Doesn't make it any less of a 'holy poo poo' situation though.

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
Reading kernel memory breaks kernel ASLR, so it's basically half a root exploit on its own.

Klyith
Aug 3, 2007

GBS Pledge Week

The Fool posted:

Doesn't make it any less of a 'holy poo poo' situation though.

yeah alright, but holy poo poo in a holy poo poo OSes need to do extensive rewrites of memory management type way

not a holy poo poo the world is ending way

The Fool
Oct 16, 2003


Let me introduce you to September 2017.

Truga
May 4, 2014
Lipstick Apathy

Klyith posted:

are you positive? the writing about this made it seem to me like the bug can only read kernel memory.

If you can read kernel memory, getting root access is probably only a matter of jumping through some hoops.

Evis
Feb 28, 2007
Flying Spaghetti Monster

If by hoops you mean find other bugs that allow you to exploit the kernel or more privileged processes to obtain root then sure.

Truga
May 4, 2014
Lipstick Apathy
You can probably find a private key that'll let you have root eventually, when you can read literally anything in memory.

OddObserver
Apr 3, 2009

Evis posted:

If by hoops you mean find other bugs that allow you to exploit the kernel or more privileged processes to obtain root then sure.

I am kinda worried about Android on Arm64...

Thanks Ants
May 21, 2004

#essereFerrari


Presumably this could be used to attack the VSM in Device Guard as well, since it would just exploit the kernel in the underlying hypervisor.

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


The Fool posted:

Let me introduce you to September 2017.

Sorry, we are now firmly into

feedmegin
Jul 30, 2008

Cup Runneth Over posted:

Sorry, we are now firmly into

Into 2014? Quick guys, I've got some dark poo poo to tell you about the upcoming Brexit referendum and US presidential election...

Diva Cupcake
Aug 15, 2005

Embargo is lifted.

Thanks Ants
May 21, 2004

#essereFerrari


https://security.googleblog.com/2018/01/todays-cpu-vulnerability-what-you-need.html

:tif:

OddObserver
Apr 3, 2009
https://googleprojectzero.blogspot.com/2018/01/reading-privileged-memory-with-side.html as well, for less summarizing, more details.

Truga
May 4, 2014
Lipstick Apathy
computers were a mistake

CLAM DOWN
Feb 13, 2007




Truga posted:

computers were a mistake

Zil
Jun 4, 2011

Satanically Summoned Citrus


Truga posted:

computers were a mistake

Thanks Ants
May 21, 2004

#essereFerrari


Truga posted:

computers were a mistake

Judge Schnoopy
Nov 2, 2005

dont even TRY it, pal
The Infosec Thread: computers were a mistake

vanity slug
Jul 20, 2010

I liked FUCKWIT more than Meltdown.

deimos
Nov 30, 2006

Forget it man this bat is whack, it's got poobrain!

Jeoh posted:

I liked FUCKWIT more than Meltdown.

That was a solution, not the problem.

The Fool
Oct 16, 2003


Diva Cupcake posted:

Embargo is lifted.

<snip bad twitter screenshot>

Here is link: https://twitter.com/nicoleperlroth/status/948684376249962496

ufarn
May 30, 2009
The Infosec Thread: Nice Meltdown, Dude

Truga
May 4, 2014
Lipstick Apathy

ufarn posted:

The Infosec Thread: Nice Meltdown, Dude

lol

CLAM DOWN
Feb 13, 2007




ufarn posted:

The Infosec Thread: Nice Meltdown, Dude

hell yes

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

ufarn posted:

The Infosec Thread: Nice Meltdown, Dude

Mods, please.

Adbot
ADBOT LOVES YOU

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

ufarn posted:

The Infosec Thread: Nice Meltdown, Dude

It is our destiny.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply