5 comments

  • mike_hearn 19 minutes ago
    The designers of the firmware anticipate this attack but punt it to the vendor, apparently:

        //
        // Platform implementor should choose a timeout value appropriately:
        
        [snip]
    
        // - The timeout value must be longer than longest possible IO operation in the system
  • Liftyee 9 minutes ago
    I don't know much about the specifics of CPU architecture apart from the existence of assembly and different modes. Either way the explanation was still entertaining and interesting. smiiiiiiii
  • nazgulsenpai 47 minutes ago
    I'm amused at the lengths the readme goes to in order to drive home the fact that this needs to be a LOOOOOOOOOOOOOOOOOOOONG instruction, including the unnecessarily long code block illustration. The topic is interesting anyway, but that makes it way more entertaining.
    • BadBadJellyBean 41 minutes ago
      Do you think a short instruction is okay or does it need to be long? The instructions were a bit unclear in that regard :D
      • nazgulsenpai 4 minutes ago
        Only if the short instruction is incredibly long.
  • londons_explore 39 minutes ago
    Unclear why there is a 1 second timeout at all.

    Presumably the patch for that will be to make it an infinity timeout.

    • xxpor 34 minutes ago
      Can this be patched? Is there a chance it's a hw watchdog that you can't fix in microcode?
    • ramses0 24 minutes ago
      Looks like it's ~4 billion (2^32) crossover counter?
  • kmeisthax 38 minutes ago
    ...huh, I was wondering why serial machine code prankster xoreaxeaxeax was keeping lists of extremely long-running instructions.

    Hopefully this is at least only possible in kernel mode, right?

    Right?!

    • tptacek 1 minute ago
      Is it really a long running instruction? I mean, obviously yes, but what makes it slow is that it's doing an MMIO copy from a slow source. It's like a read(2) system call being "slow" because the fd is associated with a socket to the moon.
    • xxpor 32 minutes ago
      Maybe with vfio/igb_uio/uio_pci_generic? Still root level access.