Subject: Re: timing attack via hyperthreading
To: None <tech-security@netbsd.org>
From: Dick Davies <rasputnik@hellooperator.net>
List: tech-security
Date: 05/15/2005 18:49:48
* Steven M. Bellovin <smb@cs.columbia.edu> [0532 16:32]:
> See ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:09.htt.asc
> 
> Briefly, the article claims that there are timing attacks on 
> hyperthreading machines that permit disclosure of, for example, 
> cryptographic keys.  The advisory I quote does not have sufficient 
> details to let me evaluate it definitively, but I would say it's 
> extremely plausible, given other results on timing attacks -- see, for 
> example, http://crypto.stanford.edu/~dabo/abstracts/ssl-timing.html

More details in:

http://www.daemonology.net/papers/htt.pdf

-- 
'Oh. Your. God.'
		-- Bender
Rasputin :: Jack of All Trades - Master of Nuns