Understanding Hardware Vulnerabilities

No ratings

Presented at BSidesAugusta 2019 by

In 2018, the world learned of Meltdown and Spectre. Before that, there was RowHammer and now a related vulnerability RAMbleed. Now in 2019 we have learned about ZombieLoad. What do all of these vulnerabilities have in common? Most people in the tech community really don't understand them well. What else do they have in common? Detecting exploitation is all but impossible with standard monitoring. This leaves infosec professionals knowing that their systems were vulnerable (and in many cases remain that way), but without a good method of detecting exploitation. This talk will clarify how these hardware vulnerabilities work in terms that even managers can understand, offer some ideas for dealing with these threats, and offer some predictions about future classes of hardware vulnerabilities. You'll leave with the tools to communicate the scope of these threats to your leadership.