Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1389279

Re: [RFC PATCH v1 00/18] x86: Secure Memory Encryption (AMD)

From Pavel Machek <pavel@ucw.cz>
Newsgroups linux.kernel
Subject Re: [RFC PATCH v1 00/18] x86: Secure Memory Encryption (AMD)
Date 2016-04-27 17:50 +0200
Message-ID <rszSW-3yc-35@gated-at.bofh.it> (permalink)
References <rsx4K-1jL-37@gated-at.bofh.it> <rsx4L-1jL-63@gated-at.bofh.it> <rsyka-2uQ-5@gated-at.bofh.it> <rsyNe-2L2-69@gated-at.bofh.it> <rsyWR-2P1-7@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Wed 2016-04-27 16:39:51, Borislav Petkov wrote:
> On Wed, Apr 27, 2016 at 04:30:45PM +0200, Pavel Machek wrote:
> > That does not answer the question. "Why would I want SME on my
> > system?".
> 
> Because your question wasn't formulated properly. Here's some text from
> the 0th mail which you could've found on your own:
> 
> "The following links provide additional detail:
> 
> AMD Memory Encryption whitepaper:
>    http://amd-dev.wpengine.netdna-cdn.com/wordpress/media/2013/12/AMD_Memory_Encryption_Whitepaper_v7-Public.pdf
> "


Unfortunately that document is marketing junk.

AFAICT:

SME can protect against cold boot attack and snooping at DRAM
level. That's pretty much it.

Does the AES encryption take the address as a parameter?

SEV may protect against passive attack on the VM. For active attack,
they claim it will "probably" crash the VM, but we already know that
is untrue, see the work on gaining root using rowhammer. In this case,
attacker can choose which address to damage and has precise control of
timing.

Best regards,
                                                                Pavel
								

-- 
(english) http://www.livejournal.com/~pavelmachek
(cesky, pictures) http://atrey.karlin.mff.cuni.cz/~pavel/picture/horses/blog.html

Back to linux.kernel | Previous | NextPrevious in thread | Find similar | Unroll thread


Thread

Re: [RFC PATCH v1 00/18] x86: Secure Memory Encryption (AMD) Pavel Machek <pavel@ucw.cz> - 2016-04-27 14:50 +0200
  Re: [RFC PATCH v1 00/18] x86: Secure Memory Encryption (AMD) Borislav Petkov <bp@alien8.de> - 2016-04-27 16:10 +0200
    Re: [RFC PATCH v1 00/18] x86: Secure Memory Encryption (AMD) Pavel Machek <pavel@ucw.cz> - 2016-04-27 16:40 +0200
      Re: [RFC PATCH v1 00/18] x86: Secure Memory Encryption (AMD) Borislav Petkov <bp@alien8.de> - 2016-04-27 16:50 +0200
        Re: [RFC PATCH v1 00/18] x86: Secure Memory Encryption (AMD) Pavel Machek <pavel@ucw.cz> - 2016-04-27 17:00 +0200
        Re: [RFC PATCH v1 00/18] x86: Secure Memory Encryption (AMD) Pavel Machek <pavel@ucw.cz> - 2016-04-27 17:50 +0200

csiph-web