Researchers use Rowhammer bit flips to steal 2048-bit crypto key
arstechnica.com
arstechnica.com
Samsung added TRR (Target Row Refresh) to their memory, see slide 15 of this 2014 presentation, http://aod.teletogether.com/sec/20140519/SAMSUNG_Investors_F....
From https://arstechnica.com/information-technology/2016/03/once-...
> Third I/O employees tested 12 varieties of DDR4 chips, and it didn't take long for eight of them to succumb to bitflipping. The first DIMM to fall was Crucial Ballistix Sport model manufactured by Micron. Ultimately, the researchers also carried out successful Rowhammer attacks against other Crucial- and Micron-branded DDR4 modules, as well as DIMMs from Geil. Interestingly, DIMMs from G.Skill were able to withstand the tests.
From the linked 2016 paper, http://www.thirdio.com/rowhammer.pdf
> Of the twelve memory modules we tested, eight showed bit flips during our 4-hour experiment. And of these eight failures, every memory module that failed at default settings was on DDR4 silicon manufactured by Micron. The Geil branded modules contained SK Hynix and the G.Skill modules contained Samsung silicon.
Turns out they do test for Rowhammer vulnerability, though I am not expert enough to know how thorough this may be:
> Test 13 - Hammer Test:
> Starting from MemTest86 v6.2, potentially two passes of row hammer testing are performed. On the first pass, address pairs are hammered at the highest possible rate. If errors are detected on the first pass, errors are not immediately reported and a second pass is started. In this pass, address pairs are hammered at a lower rate deemed as the worst case scenario by memory vendors (200K accesses per 64ms). If errors are also detected in this pass, the errors are reported to the user as normal. However, if only the first pass produces an error, a warning message is instead displayed to the user.
Also the change log explicitly mentioned support for individual CPU generations (and the last release was 2013) though I don't know how relevant that is or whether it's just cosmetics. Also phrases like "better timings detection" makes you wonder whether updates for newer types of memory are required.
There was never a time the hardware was secure though. That was always just wishful thinking. People were wirelessly reading data on CRTs back in the 90s. TEMPEST research is many decades ahead and the private sector is just waking up to side channel attacks.
Would a device like the XB1 or PS4 be susceptible to one of these cross channel attacks?
The only real difference, afaict, is the speed is achieved with higher bitwidths (512bit vs 64bit) than regular SDRAM, so it is very likely to suffer the same vulnerabilities.
I wonder if that could fix the problem?