Security
DE
Apple’s New Memory Integrity Enforcement
['Bruce Schneier']
Schneier on Security
Apple has introduced a new hardware/software security feature in the iPhone 17: “Memory Integrity Enforcement,” targeting the memory safety vulnerabilities that spyware products like Pegasus tend to use to get unauthorized system access.
When developers—even experienced and security-conscious developers—write software in ubiquitous, historic programming languages, like C and C++, it’s easy to make mistakes that lead to memory safety vulnerabilities.
[…]With memory-unsafe programming languages underlying so much of the world’s collective code base, Apple’s Security Engineering and Architecture team felt that putting memory safety mechanisms at the heart of Apple’s chips could be a deus ex machina for a seemingly intractable problem.
The group built on a specification known as Memory Tagging Extension (MTE) released in 2019 by the chipmaker Arm.
In other words, you can see how generating and attaching secrets to every memory allocation and then demanding that programs manage and produce these secrets for every memory request could dent performance.
['request'
'software'
'vulnerabilities'
'programming'
'memory'
'security'
'system'
'mte'
'languages'
'schneier'
'apples'
'safety']