Slashdot Mirror


Many DDR3 Modules Vulnerable To Bit Rot By a Simple Program

New submitter Pelam writes: Researchers from Carnegie Mellon and Intel report that a large percentage of tested regular DDR3 modules flip bits in adjacent rows (PDF) when a voltage in a certain control line is forced to fluctuate. The program that triggers this is dead simple — just two memory reads with special relative offset and some cache control instructions in a tight loop. The researchers don't delve deeply into applications of this, but hint at possible security exploits. For example a rather theoretical attack on JVM sandbox using random bit flips (PDF) has been demonstrated before.

4 of 138 comments (clear)

  1. Many DDR3 modules? by ArcadeMan · · Score: 3, Insightful

    This is all very interesting but totally pointless! Which modules? Tell us the brands, model names, manufacturer numbers?

    1. Re:Many DDR3 modules? by DigiShaman · · Score: 4, Insightful

      FTFP. "We induce errors in most DRAM modules (110 out of 129) from three major DRAM manufacturers."

      Short version, leakage current from adjacent gates can nudge other to bit-flip. I don't think this is a manufacturing problem as it is a fundamental EE design oversight. So yeah, defective by design (unintentionally)!!

      --
      Life is not for the lazy.
  2. Re:good news for ECC memory makers by sshir · · Score: 4, Insightful

    At least with ECC you'll get _some_ feedback (it's random so it will pop from time to time) indicating that something fishy is going on. With regular ram all corruptions are silent so you'll get random crashes that will drive you crazy...

  3. Using Non-ECC Ram is Unacceptable by BrendaEM · · Score: 1, Insightful

    Unless you are making a Speak-and-Spell, it's foolish not to use non-ECC RAM. I would rather pay an additional 9th as much and have some peace of mind that the RAM will at least keep from flipping a bit from comic rays, which happens about once a week.

    I take that back; put it in the Speak-and-Spell, too.

    --
    https://www.youtube.com/c/BrendaEM