
@stuntpants Any idea why hugepage support is in the M1 but not in macOS? Was surprised I couldn't even force it on from userspace...
English
David Kohlbrenner
56 posts

@dkohlbre
Software/Hardware Security Person. Assistant Professor at @uwcse. Making whole systems just a bit more secure. PPP Alum. He/Him. @[email protected]


Today @kavehrazavi and I are finally allowed to talk about #Retbleed. In 2018, #SpectreV2 was fixed by replacing indirect jumps with returns. But, returns can be poisoned like indirect jumps, throwing us us back to 2018 again. Paper, demo, addendum, code @ comsec.ethz.ch/retbleed


We found a way to mount *remote timing* attacks on *constant-time* cryptographic code running on modern x86 processors. How is that possible? With #hertzbleed! Here is how it works (with @YingchenWang96). hertzbleed.com











