Subject: timing attack via hyperthreading
To: None <tech-security@netbsd.org>
From: Steven M. Bellovin <smb@cs.columbia.edu>
List: tech-security
Date: 05/15/2005 11:31:17
See ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:09.htt.asc
Briefly, the article claims that there are timing attacks on
hyperthreading machines that permit disclosure of, for example,
cryptographic keys. The advisory I quote does not have sufficient
details to let me evaluate it definitively, but I would say it's
extremely plausible, given other results on timing attacks -- see, for
example, http://crypto.stanford.edu/~dabo/abstracts/ssl-timing.html
--Prof. Steven M. Bellovin, http://www.cs.columbia.edu/~smb