frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Battering RAM – Low-Cost Interposer Attacks on Confidential Computing

https://batteringram.eu/
39•pabs3•2h ago

Comments

schoen•2h ago
I think I talked about this possibility with Bunnie Huang about 15 years ago. As I recall, he said it was conceptually achievable. I guess it's also practically achievable!
no_time•1h ago
I find it reassuring that you can still get access to the data running on your own device, despite all the tens of thousands of engineering hours being poured into preventing just that.
throawayonthe•1h ago
I doubt you own hardware capable of any of the confidential computing technology mentioned
kedihacker•53m ago
Well microcontrollers can prevent you from repairing your own device with DRM and secure enclaves
Simple8424•1h ago
Is this making confidential computing obsolete?
Harvesterify•17m ago
In their current form, AMD and Intel proposals never fulfilled the Confidential Computing promises, one can hope they will do better in their next iteration of SGX/TDX/SEV, but they were always broken, by design.
dist-epoch•3m ago
That's like saying a security vulnerability in OpenSSL/SSH is making SSL/SSH obsolete.
fweimer•1h ago
I'm kind of confused by AMD's and Intel's response. I thought both companies were building technology that allows datacenter operators to prove to their customers that they do not have access to data processed on the machines, despite having physical access to them. If that's out of scope, what is the purpose of these technologies?
Harvesterify•20m ago
Security theater, mostly.
matja•28m ago
> No, our interposer only works on DDR4

Not surprising - even having 2 DDR5 DIMMs on the same channel compromises signal integrity enough to need to drop the frequency by ~30-40%, so perhaps the best mitigation at the moment is to ensure the host is using the fastest DDR5 available.

So - Is the host DRAM/DIMM technology and frequency included in the remote attestation report for the VM?

commandersaki•22m ago
I like how the FAQ doesn't really actually answer the questions (feels like AI slop but giving benefit of the doubt), so I will answer on their behalf, without even reading the paper:

Am I impacted by this vulnerability?

For all intents and purposes, no.

Battering RAM needs physical access; is this a realistic attack vector?

For all intents and purposes, no.

Lgbtt Heterosexuals with Fraudulent Bodies

https://92b46d1e90.cbaul-cdnwnd.com/61d60e52bc104168791c48326685c290/200000191-9b2ad9b2ae/Direct%...
1•ONLYHAAPY•1m ago•0 comments

DefiLlama to delist Aster perpetual volume data over integrity concerns

https://cointelegraph.com/news/defillama-delist-aster-perp-data-integrity
1•b16m•1m ago•0 comments

The Power of Three: Ternary Logic, Triolectics, and Three Sided Football

https://www.sothismedias.com/home/the-power-of-three-ternary-logic-triolectics-and-football
1•thomasjb•1m ago•0 comments

Hanami for Rails Developers – Part 1

https://ryanbigg.com/2025/10/hanami-for-rails-developers-1-models
1•ryanbigg•4m ago•0 comments

Leak suggests US Government is fibbing over FEMA security failings

https://www.theregister.com/2025/10/06/infosec_in_brief/
2•defrost•5m ago•0 comments

The Zionist Occupation of Open Source

https://moneo.com.tr/blog/the-zionist-occupation-of-open-source
12•selim17•12m ago•0 comments

The Debugging Book

https://www.debuggingbook.org/
2•signa11•19m ago•0 comments

Clop crew hits Oracle E-Business Suite users with fresh zero-day

https://www.theregister.com/2025/10/06/clop_oracle_ebs_zeroday/
1•jjgreen•20m ago•0 comments

Show HN: Iframetest.com

https://iframetest.com/
1•tonysurfly•20m ago•0 comments

Show HN: Fast Masked Mail Creator – Chrome Extension for Fastmail Masked Emails

https://chromewebstore.google.com/detail/fast-masked-mail-creator/jgnkjcmgagjaabogldbabgbcncakpdbb
1•tmarice•21m ago•0 comments

2 Math Problems Fall to LLM: Tsumura's 554 solved, Majority Optimality Disproved

https://nednex.com/en/two-notorious-math-problems-fall-to-llm-tsumuras-554th-solved-majority-opti...
1•SweetSoftPillow•22m ago•0 comments

Tutorials for Sandia's Lammps Simulation Package

https://arxiv.org/abs/2503.14020
1•northlondoner•23m ago•1 comments

Tone Control

https://www.robinsloan.com/lab/tone-control/
1•thomasjb•25m ago•0 comments

Build a VPN Tunnel with Wintun on Windows – Part 1

https://0xmm.in/posts/peer-to-peer-windows-part1/
2•accessonline•26m ago•1 comments

NetBird – An Open-Source Tailscale Alternative

https://netbird.io
2•akyuu•28m ago•0 comments

Nobel Prize in Physiology or Medicine 2025 awarded to immune system researchers

https://www.nobelprize.org/prizes/medicine/2025/press-release/
4•lode•34m ago•0 comments

Meta announces launch of APAC's 'largest capacity subsea cable' in 2028

https://subseacables.blogspot.com/2025/10/the-new-candle-cable-system-project.html
3•Henry3•35m ago•0 comments

-

https://engineering.fb.com/2025/10/05/connectivity/introducing-the-candle-subsea-cable-updates-to...
3•Henry3•37m ago•0 comments

Testing two 18 TB white label SATA hard drives from datablocks.dev

https://ounapuu.ee/posts/2025/10/06/datablocks-white-label-drives/
2•thomasjb•39m ago•0 comments

Love Money Harvey – Free Adult Visual Novel and Finance Game

https://lovemoneyharvey.com
1•heihieih•48m ago•0 comments

EasyOS: An Experimental Linux Distribution

https://easyos.org/
2•signa11•50m ago•0 comments

Granite-4.0-Micro: a 3.4B parameter LLM that runs in the browser

https://huggingface.co/spaces/ibm-granite/Granite-4.0-WebGPU
3•victormustar•53m ago•0 comments

Show HN: How to create your own custom decentralized lotteries

https://LotteryHouse.Me
2•scanmed•59m ago•0 comments

Cerebras Withdraws IPO Filing

https://www.sec.gov/Archives/edgar/data/2021728/000119312525230382/d886849drw.htm
3•JumpCrisscross•59m ago•1 comments

Django: One ORM to rule all databases

https://www.paulox.net/2025/10/06/django-orm-comparison/
5•pauloxnet•1h ago•0 comments

Understanding Object-Oriented Programming

https://understandingoop.com/
5•ma-px•1h ago•0 comments

The 'Best' Colleges Aren't the Best Forever

https://www.theatlantic.com/ideas/archive/2025/10/ivy-league-schools-prestige/684454/
1•FinnLobsien•1h ago•0 comments

Crypto-Current (2021)

https://zerophilosophy.substack.com/p/crypto-current
1•keepamovin•1h ago•0 comments

Full code to build your own AI agent with Python

https://thenewaiorder.substack.com/p/how-to-code-an-ai-agent-text-to-sql
4•ClaireGz•1h ago•0 comments

A terminal command that tells you if your USB-C cable is bad

https://kau.sh/blog/usbi/
1•freetonik•1h ago•0 comments