Inception – Break and Enter Using Direct Memory Access
breaknenter.org
breaknenter.org
[1] https://citp.princeton.edu/research/memory/media/
Edit: Also I wonder if there would be much worth in adding kernel interfaces to say "a new DMA-capable device was hotplugged - userspace should ask the user whether we should give them DMA access"? That would allow you to protect against these attacks without having to disable all your biz.
"No password? No hotplug for you." seems like a rule we ought to be enforcing.
"Note: Mavericks since 10.8.2 on Ivy Bridge (>= 2012 Macs)
have enabled VT-D effectively blocking DMA requests and thwarting
almost all modules."
Looks like newer models have fixed it, but your suggestion would probably be nice for older systems.http://youtu.be/iTJApG0TMBQ?t=13m18s
https://hn.algolia.com/?query=inception+firewire&sort=byDate...
But it seems that even linux set this registers to allow pretty much everything (writes to OHCI1394_PhyUpperBound in src/drivers/firmware/*.c)
What keeps the target from starting an inception attack on the host?
I guess loading the driver with DMA disabled would be a good option, as I don't think the attack needs DMA on the host side. Not sure, though, after skimming over the documentation.
"The world’s forensics experts, governments and three-letter acronym agencies are using similar tools already, so why not?"
I'm not sure I understand that reasoning, but whatever.