HN user

redrabbyte

18 karma

researcher for coresec@tugraz

Posts0
Comments17
View on HN
No posts found.

concurrent work (https://arxiv.org/ftp/arxiv/papers/2401/2401.04349.pdf) has shown website fingerprinting, recognizing something like the static login page of youtube/google/facebook etc is very much doable.

that said, I don't expect to see any of these attacks in the wild. they're primarily demonstrations of the technique and to show that the channel is there

as is often the case with side-channel attacks, a serious attacker would much more likely go for un-/recently patched traditional vulnerabilities

It's always hard to communicate fairly academic side channels in a way that the audience of a press-release (which is typically anyone) can get any level of detail.

We tried to walk the line between enough information and not overwhelming, but it doesn't always work out :D Luckily there's always the paper.

This article also did a pretty good job of a high-level summary imo https://www.securityweek.com/new-attack-shows-risks-of-brows...

the inclusivity types don't really play a role in these types of attack (until you get to a very practical stage where this might matter), not least because there are other sidechannels that can be exploited. an inclusive llc is just convenient.

that said, some newer Intel LLCs are non-inclusive, and amd changed its cache relations as well in ryzen