Tag Archive for: Potentially

Potentially disastrous Rowhammer bitflips can bypass ECC protections

A DDR3 DIMM with error-correcting code from Samsung. ECC is no longer an absolute defense against Rowhammer attacks.

Enlarge / A DDR3 DIMM with error-correcting code from Samsung. ECC is no longer an absolute defense against Rowhammer attacks. (credit: Samsung)

In early 2015, researchers unveiled Rowhammer, a cutting-edge hack that exploits unfixable physical weaknesses in the silicon of certain types of memory chips to transform data they stored. In the 42 months that have passed since then, an enhancement known as error-correcting code (or ECC) available in higher-end chips was believed to be an absolute defense against potentially disastrous bitflips that changed 0s to 1s and vice versa.

Research published Wednesday has now shattered that assumption.

Dubbed ECCploit, the new Rowhammer attack bypasses ECC protections built into several widely used models of DDR3 chips. The exploit is the product of more than a year of painstaking research that used syringe needles to inject faults into chips and supercooled chips to observe how they responded when bits flipped. The resulting insights, along with some advanced math, allowed researchers in Vrije Universiteit Amsterdam’s VUSec group to demonstrate that one of the key defenses against Rowhammer isn’t sufficient.

Read 18 remaining paragraphs | Comments

Biz & IT – Ars Technica

Air Canada reveals mobile data breach, passport numbers potentially exposed

  1. Air Canada reveals mobile data breach, passport numbers potentially exposed  ZDNet
  2. Air Canada app data breach involves passport numbers  BBC News
  3. Air Canada confirms mobile app data breach  TechCrunch
  4. Air Canada, WestJet raising baggage fee  Kelowna Capital News
  5. Full coverage

data breach – read more

Terros Health data breach: 1600 patients potentially impacted

  1. Terros Health data breach: 1600 patients potentially impacted  ABC15 Arizona
  2. Phoenix Terros Health Reports Major Data Breach; 1600 Patients Affected  KJZZ
  3. Full coverage

data breach – read more

Verizon denies data loss but admits potentially huge breach – ComputerWeekly.com

Verizon denies data loss but admits potentially huge breach
ComputerWeekly.com
“The long duration of time between the initial 13 June notification to Verizon by UpGuard of this data exposure, and the ultimate closure of the breach on 22 June, is troubling,” the security firm said. “Third-party supplier risk is business risk

and more »

data breach – Google News