3 ms·
Couldn't you syscall into the kernel to set the flag, then return back into usermode with it set?
by IAmLiterallyAB 2y ago
Couldn't you syscall into the kernel to set the flag, then return back into usermode with it set?
- amluto 2y agoSo your compiler is supposed to emit a pair of syscalls each function that does integer math? Never mind that a pair of syscalls that do WRMSR may well take longer than whatever crypto operation is between them. I have absolutely nothing good to say about Intel’s design here.
- pvillano 2y agoWhat's the alternative?
- amluto 2y agoAn instruction prefix that makes instructions constant time. A code segment bit (ugly but would work). Different instructions. Making constant time the default. A control register that’s a user register.
- convolvatron 2y agosince we already have some reasons to sign in an enclave, why not just design a cryptographic processor which is highly unoptimized and highly predictable. since the majority of codes benefit immensely from the optimizations, it doesn't seem reasonable to cripple them.
- amluto 2y agoSo instead of just doing the rather fast elliptic curve math when getting a TLS connection request by using a standard crypto library, I’m supposed to call out to a cryptographic coprocessor that may or may not even support the operation I need? Have you seen what an unbelievable mess your average coprocessor is to use, Intel or otherwise. CPUs have done just fine doing constant time math for decades. It’s at best a minor optimization to add data dependence, and Intel already knows (a) how to turn it off and (b) that it’s sometimes necessary to let it be turned off. Why can’t they add a reasonable mechanism to turn them off?
- adgjlsfhk1 2y agoThe version of this that I want to see is a CPU that gives you a core that doesn't have caches or branch prediction on which you can write custom code without having to worry about timing attacks.
- IAmLiterallyAB 2y agoYou could just leave it on. I agree it's not great.