← All writing

We Take Your Security Seriously

On this page

“We take your security seriously” - how many times has this been said in the aftermath of a breach. And how many times has it seemed a little… hollow?

Here are a couple of examples of really taking security seriously.

Nvidia

Nvidia presention at this year’s Black Hat “How to Secure Unique Ecosystem Shipping 1 Billion+ Cores?” was an interesting review of where they are and where they are going. It is not widely understood that a “GPU” contains a lot of other electronics, in addition to the main processing cores which everyone is excited about. In fact, there can be between 10 and 50 additional microprocessors within such a device. Currently they are built around an Nvidia custom architecture. In future, they will be using industry-standard RISC-V.

In order to defend against software vulnerabilities, they have combined their silicon design teams and their offensive security research teams. This led to extensions to the RISC-V architecture, created in collaboration with others, including Google. One of these extensions, pointer masking, transforms the effective address of pointers, making it much harder for attackers to exploit. A second, adds control-flow integrity (CFI) extensions. These allow the compiler toolchain to indicate to the hardware where branches should be coming from, and going to. Each indirect branch destination is a landing-pad (LPAD) instruction which contains a label. This label is set just before a legitimate branch happens. If an attacker modifies the flow of the code, either the label will not match, or the destination of their branch will not be an LPAD - either of which will raise an exception. This defends nicely against “code-reuse attacks” (like return-oriented programming etc.)

This is a lot of work, and the combination of designers and attackers across companies has resulted in some very useful features which are available to the RISC-V community.

Apple

Meanwhile, Apple has announced “Memory Integrity Enforcement”. Not content to rest on their laurels, Apple has spent the last half-decade or so also putting their threat-hunters and silicon design teams together. They have analysed a lot of data about how attackers are able to exploit Apple operating systems (which, let’s be fair, is not easy anyway), and designed a set of memory-safety mitigations within the silicon which will make attackers’ lives much harder still. Pointer Authentication was already part of Apple’s devices (and may come to RISC-V in future?), and now the Enhanced Memory Tagging Extension allows software developers to enable further defences. When memory is allocated, it is tagged, and the tags are cryptographically bound to the memory areas. Unless the process accessing the memory has the same cryptographic secret to perform the access, it will be denied. This tagging hardware is carefully designed to avoid timing leaks (for example through speculative execution).

Again, a huge investment in “non-user-visible” features which provide security behind the scenes.

This is what “We take your security seriously” looks like

A continual investment of many people across diverse teams - in particular bringing the offensive researchers into contact with the upfront design, so that priorities can be organised effectively, and trade-offs (of which there we no doubt many) can be discussed between all the right people.