3 ms·
Hi, the line about "failed" attacks pertains to the attack on AMD, Nvidia worked fine ;)
by redrabbyte 2y ago
Hi, the line about "failed" attacks pertains to the attack on AMD, Nvidia worked fine ;)
- bastawhiz 2y agoEven still, it relies on the assumption that you know that the user is typing, and that they're typing something that's interesting to you. You could pop a login page and expect the user to sign in, but it's still a very tenuous scenario to measure what you think might be keypresses. The time to redraw a text box is just as easily the focus ring being drawn, or the submit button being hovered, or a minor scroll event. Even then, the best that I know of for password recovery from timing is "Timing Analysis of Keystrokes and Timing Attacks on SSH", which relies on having data about the user in advance, and they only manage to reduce the search space by about 50x. I'm sure the state of the art is probably a bit better, but that's still assuming a lot: key press timing (that's probably noisy) isn't going to be a meaningful attack vector for arbitrary users online.
- redrabbyte 2y agoconcurrent work (https://arxiv.org/ftp/arxiv/papers/2401/2401.04349.pdf https://arxiv.org/ftp/arxiv/papers/2401/2401.04349.pdf) has shown website fingerprinting, recognizing something like the static login page of youtube/google/facebook etc is very much doable. that said, I don't expect to see any of these attacks in the wild. they're primarily demonstrations of the technique and to show that the channel is there as is often the case with side-channel attacks, a serious attacker would much more likely go for un-/recently patched traditional vulnerabilities