Linux maintainer: Patching side-channel flaws is killing performance

Mirror, mirror on the wall, which is the worst side-channel vulnerability of them all? Continue reading Linux maintainer: Patching side-channel flaws is killing performance

Side-Channel Attacks: Cyber Warfare’s New Battleground

The current state of cybersecurity is complex, fast-moving and a critical risk to all organizations. Understanding where U.S. businesses stack up in terms of their security knowledge and defense strategy is of utmost importance. It’s critical that lea… Continue reading Side-Channel Attacks: Cyber Warfare’s New Battleground

How would one compare Cache Allocating Technology against MIT’s Dynamically Allocated Way Guard for prevention of the Spectre side-channel Attack?

Upon research, I’m finding it difficult to identify a way to compare each solution. Is it correct in saying both solutions are software based? Therefore, could I compare overall PC perfomance with each software implementation… Continue reading How would one compare Cache Allocating Technology against MIT’s Dynamically Allocated Way Guard for prevention of the Spectre side-channel Attack?

This Week in Security: Zombieload, and Is Your Router Leaking?

Do you know what your router is doing? We have two stories of the embedded devices misbehaving. First, Linksys “Smart” routers keep track of every device that connects to its network. Right, so does every other router. These routers, however, also helpfully expose that stored data over JNAP/HNAP.

Some background …read more

Continue reading This Week in Security: Zombieload, and Is Your Router Leaking?

How risky would it be to run a Linux kernel without Spectre and Meltdown patches on a regular desktop system?

What would happen if we adopted: https://make-linux-fast-again.com/

Assume the system is used for development and general browsing.

Are there any cases of these vulnerabilities being exploited in the wild, (especially by we… Continue reading How risky would it be to run a Linux kernel without Spectre and Meltdown patches on a regular desktop system?

ZombieLoad: How Intel’s Latest Side Channel Bug Was Discovered and Disclosed

Daniel Gruss, the researcher behind Spectre, Meltdown – and most recently, ZombieLoad – Intel CPU side channel attacks, gives an inside look into how he discovered the flaws. Continue reading ZombieLoad: How Intel’s Latest Side Channel Bug Was Discovered and Disclosed