Bookmark and Share

Tags

32nm 40nm 45nm AMD Apple ASUS ATI Atom Blu-ray Business Cypress E-Book Evergreen Fermi Flash Geforce Globalfoundries GT300 Intel Microsoft Nintendo Nokia Nvidia OCZ Radeon Semiconductor Sony SSD USB Windows

News

Intel’s Hyper-Threading may be useful for enhancing performance, but it may also compromise security in some cases, particularly in case of servers, claims a researcher from Canada. Fortunately, it seems that patches for operating systems can correct the issue.

On Intel Pentium 4 and Xeon with Hyper-Threading processors the two threads being executed on each processor share more than the execution units, but also they share access to the memory caches. Caches have already been demonstrated to be cryptographically dangerous: many implementations of AES are subject to timing attacks arising from the non-constancy of S-box lookup timings. However, having caches shared between threads provides a vastly more dangerous avenue of attack, claims Colin Percival, a researcher who has spent about half a year investigating the matter.

According to a document released Friday, this shared access to memory caches pro-vides not only an easily used high bandwidth covert channel between threads, but also permits a malicious thread (operating, in theory, with limited privileges) to monitor the execution of another thread, allowing in many cases for theft of cryptographic keys.

The security flaw hardly affects desktop users, but server administrators should pay attention to the situation. It is also unclear whether sharing of memory caches between threads may confront security within systems running dual-core processors.

The author provides some suggestions to processor designers, operating system vendors, and the authors of cryptographic software, of how this attack could be mitigated or eliminated entirely.

Intel’s reaction on the allegations was unavailable at press time.

Discussion

Comments currently: 1
Discussion started: 05/14/05 12:02:11 PM
Latest comment: 05/14/05 12:02:11 PM

[1-1]

1. 
Worrying... this is certainly something to consider when implementing virtualization, also.

By the way, the main reason I'm making this comment is because of your subtitle--very witty; made me laugh, anyway. :)
[Posted by: MTX  | Date: 05/14/05 12:02:11 PM]

[1-1]

You must log in to add comments.

Forgot password? Registration

remember me



Related news

Latest News

Wednesday, November 25, 2009

2:36 pm | EA Montreal to Concentrate on High-Def Games, Lower Focus on Wii. Large Video Game Developer to Re-Focus on HD Blockbuster Titles

11:58 am | AMD to Describe 32nm Bobcat Processor at Chip Conference. AMD to Reveal Power Trimming Technologies of Bobcat

Tuesday, November 24, 2009

11:50 pm | Nvidia to Start Shipping Next-Generation Tegra to Developers “Soon”. Nvidia Readies Second-Generation Tegra SoC for Handhelds

10:37 pm | Despite Netbook Popularity, Consumers Still Want Notebooks – IDC. Even in Asia, Consumers Still Prefer Notebooks over Netbooks

4:04 pm | Imagination Intros Processors for “Internet Everywhere” Consumer Electronics. Imagination Presents Connected Processors for CE Devices

3:33 pm | Sub-$99 Blu-Ray Players Black Friday Deals Available, But Not a Lot. Walmart to Sell BD Players for $78 on Black Friday

12:27 pm | Microsoft Sued for Banning Third-Party Xbox Memory Cards. Memory Cards Supplier Sues Microsoft

11:55 am | OCZ to Release External USB 3.0 Solid-State Drive. OCZ USB 3.0 SSD Incoming for Consumer Electronics Show

7:52 am | Nvidia’s CEO Expects Underpowered Mobile Devices to Gain Popularity. PC of the Future – Web-Based Device with 4G Connectivity, Says Chief Exec of Nvidia