Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
amelius
on May 26, 2021
|
parent
|
context
|
favorite
| on:
M1racles: An Apple M1 covert channel vulnerability
The OS can scan the program for instructions that access these bits. If necessary on a per-basic-block basis.
saagarjha
on May 26, 2021
[–]
Of course, this only works if you can't introduce new code without the kernel noticing.
amelius
on May 26, 2021
|
parent
[–]
Yes, you can introduce new code but the kernel should also watch for that (JIT compilation etc.) and check the resulting code. It's quite involved, and the whole process looks more like a sandbox or emulator, but it's possible.
saagarjha
on May 26, 2021
|
root
|
parent
[–]
Doing this performantly is going to be very prohibitive.
amelius
on May 26, 2021
|
root
|
parent
[–]
Perhaps (depends also on CPU support), but on the other hand: in today's world with untrusted apps, the kernel will have to do some sandboxing anyway.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: