comp.lang.ada
 help / color / mirror / Atom feed
From: kilgallen@eisner.decus.org (Larry Kilgallen)
Subject: Re: Trusting GNAT for security software
Date: 1998/03/02
Date: 1998-03-02T00:00:00+00:00	[thread overview]
Message-ID: <1998Mar2.080639.1@eisner> (raw)
In-Reply-To: m3btvp1zo2.fsf@fred.muc.de


In article <m3btvp1zo2.fsf@fred.muc.de>, Andi Kleen <ak@muc.de> writes:

> Another funny thing. Most newer Intel chips (PPro+) are rumoured to have
> loadable Microcode [SCO apparently once released a OS update that fixed
> microcode bugs]. Now you could patch the microcode to detect some known
> codes...

That was a feature of the better VAXes for years.

Now with Alpha, there is PALcode which provides the same capability
in a bit more chip-independent fashion.  It turns out you cannot
intercept arbitary (implemented) instructions, but you can certainly
get all the calls to privileged OS features, which is quite enough to 
be concerned about for security purposes.

So GNAT (or any other compiler) is just one in a long list of possible
security risks, and the primary malice risk is probably the operators
you hire for your own site rather than the compiler writers who likely
do not know (or care) that your project is using their compiler.

Larry Kilgallen




      reply	other threads:[~1998-03-02  0:00 UTC|newest]

Thread overview: 18+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
1998-02-25  0:00 Compiling gnat into gcc-2.8.0 Kevin Taylor
1998-02-26  0:00 ` Simon Wright
1998-02-26  0:00   ` Robert Dewar
1998-02-26  0:00 ` Stephen Leake
1998-02-26  0:00   ` Robert Dewar
1998-02-27  0:00   ` Markus Kuhn
1998-02-27  0:00     ` Robert Dewar
1998-02-27  0:00       ` Andi Kleen
1998-02-27  0:00         ` Larry Kilgallen
1998-02-27  0:00           ` Robert Dewar
1998-02-27  0:00     ` Richard Kenner
1998-03-01  0:00       ` Trusting GNAT for security software Markus Kuhn
1998-03-01  0:00         ` Robert Dewar
1998-03-01  0:00           ` Larry Kilgallen
1998-03-01  0:00             ` Robert Dewar
1998-03-02  0:00               ` Larry Kilgallen
1998-03-02  0:00             ` Andi Kleen
1998-03-02  0:00               ` Larry Kilgallen [this message]
replies disabled

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox