3 ms·
Decade and a half, even. If I remember right, the first CVE for an HT security flaw was summer 2005.
by ivl 7y ago
Decade and a half, even. If I remember right, the first CVE for an HT security flaw was summer 2005.
- cperciva 7y agoI announced it publicly 14 years ago yesterday.
- mmastrac 7y agoThis one? https://nvd.nist.gov/vuln/detail/CVE-2005-0109 https://nvd.nist.gov/vuln/detail/CVE-2005-0109 Dang: "Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack on memory cache misses." Also, found elsewhere: "According to Linus Torvalds and others on linux-kernel this is a theoretical attack, paranoid people should disable hyper threading"
- cperciva 7y agoYes. Intel dismissed it at the time, saying that "nobody would ever have untrusted code running on the same hardware on which cryptographic operations are performed".