9 ms·
The severity and number of side-channel attacks is slowly becoming cripplingly ridiculous. At what point do we just give up with side-channel attacks on consume
by aetherspawn 5y ago
The severity and number of side-channel attacks is slowly becoming cripplingly ridiculous. At what point do we just give up with side-channel attacks on consumer devices and assume the mentality that all consumer devices connected to the internet should be treated as insecure by default.
- ccouzens 5y agoNext week on HN: School teachers able to determine which students have been using their phones in class by looking at battery charge before and after.
- Scoundreller 5y agoWas going to guess it was by microscopic blackouts every second where sensors would detect the source of any light that remains.
- fragmede 5y agoStarting at least several years ago, if not a decade. The security industry has had this policy towards IoT devices before the technology was even cheap enough to mass produce.
- badRNG 5y ago> At what point do we just give up with side-channel attacks on consumer devices and assume the mentality that all consumer devices connected to the internet should be treated as insecure by default. There is always an endless stream of vulnerabilities for every piece of tech you use: software, OS, router, etc. This fact is not a good reason to embrace security nihilism, for consumer devices, routers, or servers. When any vulnerability is found, it should be remediated within reason (likelihood of exploitation, severity of exploit) and life should go on until the next one is found. That's one of the persistent costs of using technology.
- westurner 5y ago> assume the mentality that all consumer devices connected to the internet should be treated as insecure by default. "Zero trust security model" https://en.wikipedia.org/wiki/Zero_trust_security_model https://en.wikipedia.org/wiki/Zero_trust_security_model : > The main concept behind zero trust is that devices should not be trusted by default, even if they are connected to a managed corporate network such as the corporate LAN and even if they were previously verified.