4 ms·
Here are a few for a start: - "Cross-VM Side Channels and Their Use to Extract Private Keys" http://www.cs.unc.edu/~reiter/papers/2012/CCS.pdf http://www.cs.un
by sweis 13y ago
Here are a few for a start:
- "Cross-VM Side Channels and Their Use to Extract Private Keys" http://www.cs.unc.edu/~reiter/papers/2012/CCS.pdf http://www.cs.unc.edu/~reiter/papers/2012/CCS.pdf
- "Cache-timing attacks on AES" http://cr.yp.to/antiforgery/cachetiming-20050414.pdf http://cr.yp.to/antiforgery/cachetiming-20050414.pdf
- "Hey, You, Get Off of My Cloud: Exploring Information Leakage in Third-Party Compute Clouds" http://www.cs.cornell.edu/courses/cs6460/2011sp/papers/cloudsec-ccs09.pdf http://www.cs.cornell.edu/courses/cs6460/2011sp/papers/cloud...
- "System-Level Protection Against Cache-Based Side Channel Attacks in the Cloud" http://pdos.csail.mit.edu/~taesoo/pubs/2012/stealthmem/stealthmem-slides.pdf http://pdos.csail.mit.edu/~taesoo/pubs/2012/stealthmem/steal...
In my mind, cache-timing attacks are fairly easily solved, but may be platform dependent. However, VM escapes in general are still a concern.
- e3pi 13y ago> - "Cache-timing attacks on AES" http://cr.yp.to/antiforgery/cachetiming-20050414.pdf http://cr.yp.to/antiforgery/cachetiming-20050414.pdf Sixteen years later.... "....These pages will eventually be open to the public. Right now they are inaccessible pending resolution of my court case." Re: MCS 494, Cryptography, Spring 1997 This is an online introduction to cryptography. It is based on the web pages that I wrote for my MCS 494 course at UIC. http://cr.yp.to/crypto.html http://cr.yp.to/crypto.html See: The main repository of information on Bernstein v. United States used to be http://www.eff.org/bernstein http://www.eff.org/bernstein, subsequently moved to https://www.eff.org/cases/bernstein-v-us-dept-justice https://www.eff.org/cases/bernstein-v-us-dept-justice. This page is now much more comprehensive; you should change your bookmark to point to http://export.cr.yp.to http://export.cr.yp.to. http://cr.yp.to/export.html http://cr.yp.to/export.html
- tptacek 13y agoHuh? His papers are public. The only thing unpublished on that site is an old crypto class from the '90s.
- e3pi 13y agoExactly. The question is, what possible legal justification argues for censoring the 90's course material regarding his Bernstein v. United States?
- tptacek 13y agoThere isn't one. He could publish it if he wanted to. He just doesn't want to. That page is ancient. And none of this has anything to do with this story.
- e3pi 13y ago>There isn't one. He could publish it if he wanted to. He just doesn't want to. Incorrect. "....These pages will eventually be open to the public. Right now they are inaccessible pending resolution of my court case." >And none of this has anything to do with this story. Wrong again: >...will make it harder for people to understand how crypto and hardware work, which is a shame. -tptacek Advice: In the future, as you reply to other's comments, read carefully with due consideration or you will continue to shoot yourself in the foot.
- tptacek 13y agoI don't think you know what you're talking about. There are much more comprehensive US academic crypto resources than Bernstein's old page. Researchers routinely publish crypto research. The page you're pointing to is an artifact of '90s crypto policy.
- e3pi 13y agoI know enough to know it requires years of study to participate with "...Researchers routinely publish crypto research." For many of us on HN, including myself, what is more valuable is what is canonical textbook and more accessible. I would welcome being facile in '90s crypto policy'.