![]() |
|
Message-ID: <ME0P300MB0713281A495B6839F6E361AFEE19A@ME0P300MB0713.AUSP300.PROD.OUTLOOK.COM> Date: Sat, 27 Sep 2025 08:43:22 +0000 From: Peter Gutmann <pgut001@...auckland.ac.nz> To: Demi Marie Obenour <demiobenour@...il.com>, "oss-security@...ts.openwall.com" <oss-security@...ts.openwall.com>, "Adiletta, Andrew" <ajadiletta@....edu>, Solar Designer <solar@...nwall.com>, Andrew Cooper <andrew.cooper3@...rix.com>, "jcb62281@...il.com" <jcb62281@...il.com> CC: "openssh@...nssh.com" <openssh@...nssh.com>, "Tol, Caner" <mtol@....edu>, "Sunar, Berk" <sunar@....edu>, "Doroz, Yarkin" <ydoroz@....edu>, "Todd C. Miller" <Todd.Miller@...rtesan.com> Subject: Re: Re: [EXT] Re: CVE-2023-51767: a bogus CVE in OpenSSH Demi Marie Obenour writes: >Is there something about Rowhammer specifically that makes it an unattractive >attack, even for nation-state attackers against well-protected targets? Not Rowhammer specifically, there are a near-infinite number of gee-whiz conference-paper-worthy attacks that fall into the same category. Attackers know what works and that's what they go for. To see what works, look at any survey of attacks, for example the OWASP Top Ten. Rowhammer is at position 26,672 in that list, right next to Spectre and and Meltdown and Zenbleed and using a reflection in someone's eyeball in a selfie that shows a reflection on a window that has a reflection on a glass-encased wall image that has a reflection of a monitor that displays a password. There's no point worrying about Mission-Impossible attacks when all an attacker has to do is buy the account credentials from an exploit broker or something similar. Cool attacks and countermeasures are fun to talk about, but if you want to make the system more secure you need to fix the things that actually matter. Peter.
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.