3 ms·
While not an in the wild big, I was a disbeliever that it could even be exploited from a browser, but just last year Google proved me wrong https://security.goo
by joe_guy 5y ago
While not an in the wild big, I was a disbeliever that it could even be exploited from a browser, but just last year Google proved me wrong https://security.googleblog.com/2021/03/a-spectre-proof-of-concept-for-spectre.html?m=1 https://security.googleblog.com/2021/03/a-spectre-proof-of-c...
- userbinator 5y agoIf you have a precise enough timing and the machine is quiet enough, then yes you could always do it given enough time, but the question then becomes how to interpret the data that you do manage to read. Keys look like random data, and passwords are probably recognisable with enough semiautomated effort; but even if you manage to isolate those "needles in the haystack", you still have next to no idea what "lock" the key is for.
- Groxx 5y agoI suppose this may be one unintended point in a crappy antivirus's favor: by slowing down everything and causing a ton of CPU noise, it might make these kinds of things harder to exploit.
- Karliss 5y ago> Key looks like random data Not always. When using AES algorithm the key gets expanded and the expanded form can be distinguished from random data. Combination of RSA private key and public parameters should also be distinguishable from random data due to integer multiplication properties RSA uses. There are tools for searching encryption keys in program memory using such tricks to recognize them. Such tools would typically be used when a program like game or DRM media player runs on attacker controlled computer, but in theory would also help when fragments of memory can be leaked from a server due to side channel attacks or bugs like heart bleed.