Subject: re: working around that hyperthreading timing attack?
To: matthew green <mrg@eterna.com.au>
From: Andrew R. Reiter <arr@watson.org>
List: tech-security
Date: 05/25/2005 01:49:46
On Wed, 25 May 2005, matthew green wrote:
:
: There are no code changes, the workaround is simply to disable HT in
: the BIOS. There may be some code changes later, if it's determined
: that they can feasibly provide any benefit - it's not entirely clear
: that they can.
:
:
:of course code patches could help -- do not spin up logical cpus,
:only the physical ones.
:
Or fixing the scheduler and perhaps pieces of code that might be targetted
by attackers (ie., OpenSSL RSA implementation -- there are ways to, while
degrading performance, make it "more secure" against these types of
attacks).
--
Andrew R. Reiter
arr@watson.org