Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> The most interesting challenge here is protecting against PCIe's Address Translation Services (ATS). Using this feature, any device can claim it's using an address that's already been translated, and thus bypass IOMMU translation. For trusted devices, this is a useful performance improvement. For untrusted devices, this is a big security threat.

I wonder whether operating systems disable this by default. As far as I know modern linux versions try to use the IOMMU to isolate devices by default, but that would bypass it.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: