←back to thread

Memory Integrity Enforcement

(security.apple.com)
458 points circuit | 4 comments | | HN request time: 0.916s | source
Show context
rs_rs_rs_rs_rs ◴[] No.45186893[source]
This looks amazing, I cannot wait to see how attackers pivot.
replies(1): >>45187488 #
1. _diyar ◴[] No.45187488[source]
https://xkcd.com/538/
replies(1): >>45188405 #
2. 5f3cfa1a ◴[] No.45188405[source]
I hate this comic because it is profoundly lazy, and I hate it when people hand-wave away meaningful security advances with it.

Hitting people with wrenches leaves marks that can be shown to the media and truth & reconciliation commissions. Wetwork and black-bagging dissidents leaves records: training, operational, evidence after the fact. And it hardly scales – no matter what the powers at be want you to think, I think history shows there are more Hugh Thompsons than Oskar Dirlewangers, even if it takes a few years to recognize what they've done.

If we improve security enough that our adversaries are _forced_ to break out the wrenches, that's a very meaningful improvement!

replies(1): >>45188461 #
3. kridsdale3 ◴[] No.45188461[source]
OK sure, but you don't really need to scale, just find the one guy with $500,000,000 in BTC that you want and hit him.
replies(1): >>45188791 #
4. 5f3cfa1a ◴[] No.45188791{3}[source]
Again, lazy!

Yes: if you have half of a billion dollars in BTC, sure – you're a victim to the wrench, be it private or public. If you're a terrorist mastermind, you're likely going to Gitmo and will be placed in several stress positions by mean people until you say what they want to hear.

Extreme high-value targets always have been, and always will be, vulnerable to directed attacks. But these improvements are deeply significant for everyone who is not a high-value target – like me, and (possibly) you!

In my lifetime, the government has gone from "the feds can get a warrant to record me speaking, in my own voice, to anyone I dial over my phone" to "oh, he's using (e2e encrypted platform) – that's a massive amount more work if we can even break it". That means the spectrum of people who can be targeted is significantly lower than it used to be.

Spec-fiction example: consider what the NSA could do today, with whisper.cpp & no e2e encrypted calls.