bk99.de entertain the web since 1997

Rowhammer.js: Hardware faults from the browser

Summary

Clémentine Maurice and Daniel Gruss show how repeated memory accesses cause DRAM bit flips and how even JavaScript can become a hardware-level attack surface. Rowhammer.js demonstrated a remote, software-induced hardware fault from JavaScript. Abstraction boundaries do not prevent attacks on shared physical resources.

Ideas

  • Frequent accesses to DRAM rows can flip bits in neighbouring rows.
  • Cache eviction forces the actual memory accesses that are needed.
  • JavaScript can trigger precise microarchitectural effects despite its sandbox.
  • Through memory layout and repetition, a random bit flip becomes a building block for an exploit.
  • Hardware assumptions sit invisibly beneath operating system and browser isolation.
  • Side channels and fault attacks exploit shared, observable microarchitecture.

Insights

  • Software isolation inherits all the unspoken reliability assumptions of the hardware.
  • Remote code does not need privileges to influence physical states in a targeted way.

Quotes

  • Root privileges for web apps? – title of the talk

Habits

  • Maurice and Gruss reduce the attack to measurable memory and cache operations.

Facts

  • Clémentine Maurice and Daniel Gruss gave the talk together.

References

Critique

  • Exploitability depends heavily on DRAM, platform, browser and countermeasures.
  • The title states the maximum consequence in a pointed way, not the effect of every bit flip.

Remarks

  • The talk turned what seemed to be a reliability issue into a browser-side security problem.
  • Later Rowhammer variants bypassed several of the protections introduced at first.

Recommendations

  • Include known hardware faults in sandbox threat models.
  • Update firmware, browsers and kernels against known Rowhammer techniques.
  • Use ECC as an additional error control, not as the only defence.

Watch the talk

Search the Web Archive