Subject: re: working around that hyperthreading timing attack?
To: matthew green <mrg@eterna.com.au>
From: Andrew R. Reiter <arr@watson.org>
List: tech-security
Date: 05/25/2005 01:49:46
On Wed, 25 May 2005, matthew green wrote:

:   
:   There are no code changes, the workaround is simply to disable HT in
:   the BIOS.  There may be some code changes later, if it's determined
:   that they can feasibly provide any benefit - it's not entirely clear
:   that they can.
:
:
:of course code patches could help -- do not spin up logical cpus,
:only the physical ones.
:

Or fixing the scheduler and perhaps pieces of code that might be targetted 
by attackers (ie., OpenSSL RSA implementation -- there are ways to, while 
degrading performance, make it "more secure" against these types of 
attacks).  

--
Andrew R. Reiter
arr@watson.org