security flaw in hyper threading

Discussion in 'Intel' started by Ed Zeppelin, May 13, 2005.

  1. Ed Zeppelin

    Ed Zeppelin Guest

    Ed Zeppelin, May 13, 2005
  2. Ed Zeppelin

    Yousuf Khan Guest

    Yousuf Khan, May 13, 2005
  3. Ed Zeppelin

    David Magda Guest

    The paper (entitled "Cache Missing for Fun and Profit") is now
    available in PDF form:


    To give away the ending, it's a information disclosure issue.
    David Magda, May 14, 2005
  4. The effect is real, but presupposes that you can force a trusted
    application to use a key in one thread at the same time your hack runs
    in another on the same CPU. In practice this is not easy unless the
    machine is otherwise idle.
    Bill Davidsen, May 26, 2005
  5. Ed Zeppelin

    Neo Guest

    Hmmm.... Interesting. The "chicken little" approach taken by the author is
    a bit extreme. As with any security issue, the overall security is only as
    strong as the weakest link. I don't believe that for most systems, this
    level of effort is needed to break the security.

    This is a good paper however and the approach is very enlighting. This is
    not significantly different than other characteristic measurement approaches
    used in the past. Maybe the folks who write encrypting/decrypting code need
    to be aware of the potential for exploit and to add "noise" to those
    applications so as to bury the true details of the function. This won't
    help performance, but aren't we rapidly getting to a point where speed
    doesn't matter since we have plenty of it?

    anonymous ;-)

    well, not really - we can all be tracked. Have you changed your IP address
    Neo, May 27, 2005
