Light

Episode #875 Quiz

The PACMAN Attack
Date: 2022-06-14 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

PACMAN exploits speculative execution against ARM Pointer Authentication on Apple M1 chips. By leaking PAC verification results through microarchitectural side channels, an attacker can brute-force 11-31-bit PACs without crashes, even from user space, and forge kernel pointers. Mitigation depends on software fixes and stronger pointer-space budgeting.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode, what is the key distinction Steve drew between Apple’s Passkeys approach and SQRL when it comes to sharing access with another person?
Question 2: What specific mechanism did the PACMAN researchers use to avoid crashes while still learning whether a guessed PAC was correct?
Question 3: How many pointer-authentication bits did Steve say were left available on macOS 12.2.1 for M1 pointers after Apple used 48 bits for addressing?
Question 4: What did the researchers say about the practical visibility of a PACMAN attack if someone were trying to detect it?
Question 5: What was Steve’s proposed improvement to Apple’s use of Pointer Authentication to make brute forcing significantly harder?
Cancel