What I want to know is if this works on ECC memory. I'm guessing not, which makes the "vulnerability" even more of a non-issue in mission-critical applications that likely moved to ECC a while ago.
See here: https://www.vusec.net/projects/eccploit/
Afaik, yes it can (unless you're counting HW_EVENT_ERR_CORRECTED). They specifically try to get 1 or 3 bit flips, never 2.
See here: https://www.vusec.net/projects/eccploit/
(yes, that's the same link)
It's definitely possible in theory. You'd need four bit flips rather than three, so you'd probably need more time between accesses to the victim row, but thats a quantitative improvement at best. This can be mitigated by using different ECC bit encodings per memory location[0], so hammered data, with correct ECC for its row, always has wrong ECC values for the adjacent rows, but I don't think anyone does that.
0: This is important in order to make fake ECC memory, which uses a (cheap) combinatoric circuit in place of a (more expensive) ninth DRAM chip, not work, so it should be happening even without Rowhammer, but AFAIK it isn't.
Have you, personally, tested your servers to make sure the driver correctly handles bit errors? Can't say I have.
a) Attackers would have to develop the POC. This will require a somewhat different skillset than typical exploitation, so there's effort involved.
b) Rowhammer is best for privilege escalation. For desktop users (where the most money is) privesc is already pretty trivial - no need for fancy exploits, you can pretty much just ask for root or use a much more straightforward exploit.
c) Exploit devs don't typically like a lot of attention. You don't want to be the first person selling rowhammer exploits unless you can charge out the ass for it, because you're gonna get way more attention for it.
These incentives aren't super technical, they're mostly market driven, and it's why we don't see fancier attacks in practice, even if they're practical. As one attacker I know was saying to me, they wish they had an excuse to do the fancy thing, but it's never worth the investment when you can own boxes way more easily. Another hacker said "I don't want a Krebs article on me because I did something clever".
NSA's incentives are not super difference, except they're not as directly financial. They also have crazy resources to fuck around with this stuff, so it would make sense that they'd demo it in a lab. Would they actually deploy it? Eh, doubtful. Against another advanced defender rowhammer should be pretty detectable by monitoring ECC metrics, and again, why would you do something fancy when you can just buy 0days - the USG purchases hundreds a year from private companies and develops more themselves.