11 comments

  • mike_hearn 23 minutes ago

    The designers of the firmware anticipate this attack but punt it to the vendor, apparently:

        //
        // Platform implementor should choose a timeout value appropriately:
        
        [snip]
    
        // - The timeout value must be longer than longest possible IO operation in the system
  • Liftyee 13 minutes ago

    I don't know much about the specifics of CPU architecture apart from the existence of assembly and different modes. Either way the explanation was still entertaining and interesting. smiiiiiiii

  • nazgulsenpai an hour ago

    I'm amused at the lengths the readme goes to in order to drive home the fact that this needs to be a LOOOOOOOOOOOOOOOOOOOONG instruction, including the unnecessarily long code block illustration. The topic is interesting anyway, but that makes it way more entertaining.

      BadBadJellyBean an hour ago

      Do you think a short instruction is okay or does it need to be long? The instructions were a bit unclear in that regard :D

        nazgulsenpai 8 minutes ago

        Only if the short instruction is incredibly long.

  • londons_explore 43 minutes ago

    Unclear why there is a 1 second timeout at all.

    Presumably the patch for that will be to make it an infinity timeout.

      xxpor 38 minutes ago

      Can this be patched? Is there a chance it's a hw watchdog that you can't fix in microcode?

      ramses0 28 minutes ago

      Looks like it's ~4 billion (2^32) crossover counter?

  • kmeisthax 42 minutes ago

    ...huh, I was wondering why serial machine code prankster xoreaxeaxeax was keeping lists of extremely long-running instructions.

    Hopefully this is at least only possible in kernel mode, right?

    Right?!

      tptacek 5 minutes ago

      Is it really a long running instruction? I mean, obviously yes, but what makes it slow is that it's doing an MMIO copy from a slow source. It's like a read(2) system call being "slow" because the fd is associated with a socket to the moon.

      xxpor 37 minutes ago

      Maybe with vfio/igb_uio/uio_pci_generic? Still root level access.