Spaghettifying DRAM
把AMD DRAM地址打乱机制逆向到寄存器级,揭露PSP与微码背后的内存加密死角,硬件安全硬核干货
Article URL: https://github.com/xoreaxeaxeax/skitter-creek-bath-salts Comments URL: https://news.ycombinator.com/item?id=49286341 Points: 455 # Commen…
把AMD DRAM地址打乱机制逆向到寄存器级,揭露PSP与微码背后的内存加密死角,硬件安全硬核干货
Article URL: https://github.com/xoreaxeaxeax/skitter-creek-bath-salts Comments URL: https://news.ycombinator.com/item?id=49286341 Points: 455 # Commen…
别小看这几行汇编:这里用 512 字节 FPU/MMX/XMM 状态配合 MMIO 读取,上演 PCIe 根复合体饱和与 Rowhammer 式 hammer loop,底层硬件攻击者的灵感库。
Article URL: https://github.com/xoreaxeaxeax/asm-hall-of-shame Comments URL: https://news.ycombinator.com/item?id=49214098 Points: 188 # Comments: 42
为自主AI打造硬件级身份认证标准,直击AI信任与溯源痛点,值得关注。
Article URL: https://github.com/Willbass65/SEAI-Identity-Standard Comments URL: https://news.ycombinator.com/item?id=49205086 Points: 1 # Comments: 0
欧盟数字身份钱包强制依赖硬件级安全认证,引发第三方系统兼容性质疑,看点十足。
IT之家 8 月 3 日消息,据科技媒体 neowin 今天报道,参与欧盟数字身份钱包(EUDI Wallet)App 开发的合作方已确认,该应用程序必须依赖硬件级安全认证才能运行。 开发团队表示:“硬件级安全认证是必要要求,我们无法简单移除。” 同时,开发团队将在后续发布安全审计报告,说明该认证带…
TPM密钥永不离芯片,Go实现TLS 1.3安全认证,开源项目带你玩转硬件级加密
Article URL: https://github.com/bschaatsbergen/go-tpm-tls Comments URL: https://news.ycombinator.com/item?id=49062316 Points: 2 # Comments: 1
微软强化激活安全,TPM硬件证明封堵KMS盗版路径,企业需关注部署变化。
IT之家 7 月 26 日消息,在推出 Windows 11 后,微软要求整个 PC 产业将可信平台模块(TPM)作为所有新主板和处理器的标准配置。如今,微软正进一步利用这一已广泛普及的硬件,加强企业市场 Windows 的激活安全机制。 微软近日宣布,将为 Windows 批量激活服务(KMS,K…
LLM与检测器闭环协作,自适应生成硬件木马,突破传统RTL安全测试局限。
arXiv:2601.17178v2 Announce Type: replace-cross Abstract: Hardware Trojans (HTs) remain a critical threat because learning-based detectors often overf…
苹果A12/A13芯片曝致命BootROM硬件漏洞,影响iPhone 11系列等,且无法通过软件修复。
IT之家 6 月 19 日消息,安全公司 Paradigm Shift 昨日(6 月 18 日)发布博文,宣布在苹果 A12 和 A13 芯片上发现 BootROM 漏洞, 将其命名为 usbliter8。 在受影响机型方面,该漏洞影响搭载 A12 和 A13 芯片的设备,涵盖 iPhone XS、…
用Yubikey生成GitHub短期令牌?探讨硬件安全密钥在API访问中的创新应用。
So I was thinking, with all these sophisticated attacks on package managers, that I should use a yubikey more. One problem I wanted to solve for mysel…
技术人热议TPM是否安全:一边是社区质疑,一边是NSA推荐,硬件信任如何选择?
There's a widespread idea in the technical community that TPMs don't provide any security: - https://news.ycombinator.com/item?id=37435450 - https://l…
一种基于硬件根信任的零信任运行时强制架构,专为高频策略更新的代理型AI系统提供安全治理。
arXiv:2605.17909v2 Announce Type: replace Abstract: As autonomous agentic systems scale across regulated critical infrastructures, the lack of mechani…