#sidechannel — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #sidechannel, aggregated by home.social.
-
Cloudflare Workers Spectre Leaks JWT Tokens
Researchers extract authentication tokens from co-located cloud workers at 12 bits per second, 360 times faster than a 2021 attack
https://pulseofnations.lol/cloudflare-workers/
#CloudSecurity #Cloudflare #JwtLeak #Research #SideChannel #Spectre #Vulnerability #WebSecurity
-
I'm having a great time at #DIMVA2026 in Chania. 🙂
Today, @hweissi and @wayna from our group presented their papers "FROST: Fingerprinting Remotely using OPFS-based SSD Timing" and "Fast and Secure LLC Caches via Spatial Windows", respectively.
Tomorrow, I will be presenting our mitigation against #SnailLoad-style attacks in "Client-Side Mitigation of Remote Latency Side-Channel Attacks".
-
Mit der Technik #FROST können Websites über #JavaScript die #SSD-Aktivität von Besuchern analysieren und so offene Tabs oder Apps erkennen.
Grundlage ist ein sogenannter #SideChannel, der Zeitunterschiede bei Speicherzugriffen im #Browser misst. Dafür wird das Origin Private File System genutzt.
Die Methode gilt als komplex, zeigt aber neue Risiken für den #Datenschutz. Browserhersteller prüfen Gegenmaßnahmen.
-
#Sidechannel attacks are alive and kicking, and now with #AI
#cybersecurity
https://arstechnica.com/security/2026/05/websites-have-a-new-way-to-spy-on-visitors-analyzing-their-ssd-activity/ -
Air gaps don't stop sound.
USAT (Ultrasonic Sub-Audible Trojan) — acoustic covert channel operating at 17–22kHz, inaudible, cross-device, no physical access required.
Full research: researchgate.net/publication/404012350
-
Ich kann meinen Account noch so stark absichern, #MFA, #biometrie, #faceid – es braucht manchmal bloß eine einzige Rechnungsnummer, um Zugang zu erhalten.
https://www.gamepro.de/artikel/psn-account-kann-gehackt-werden-mit-rechnung,3445381.html
Gutes Vergleichsbeispiel, um einen #sidechannel-Angriff auf Software zu erklären, denke ich.
-
@kuketzblog Die Einstellung gibt es bei https://molly.im/ jedoch nicht bei Signal(Android), Herr Kuketz.
Um dies gänzlich zu beheben, muss es von Signal (Client + Server) gepatched werden.
Die Molly-Entwickler wollen jedoch ebenfalls Custom-Fixes bereitstellen.
https://github.com/mollyim/mollyim-android/issues/646
Signals Antwort lässt sich hier finden.
https://github.com/signalapp/Signal-Android/pull/14463#issuecomment-3613869569
P.S.: Signal ist nach wie vor sicher. Coole Kids nutzen Molly. 😁 MfG 🙏
-
藍牙 AES 的 side-channel attack
#aes #attack #bluetooth #channel #encryption #learning #machine #privacy #security #side #SideChannel
-
No fix yet for attack that lets hackers pluck 2FA codes from Android phones - Android devices are vulnerable to a new attack that can cove... - https://arstechnica.com/security/2025/10/no-fix-yet-for-attack-that-lets-hackers-pluck-2fa-codes-from-android-phones/ #sidechannel #pixnapping #security #android #privacy #biz #google
-
I have just presented our paper on Zero Click SnailLoad at ESORICS 2025 in Toulouse. Thank you to all who attended my talk, also for the nice discussion!
Also thanks to @c1t for taking the picture!
-
Security is hard.
The TL;DR is: Do not lose possesion of your private key.
Addendum: This is from a year ago to be clear. But, there are many people that have older Yubikeys that Can Not be fixed.
The attack requires physical access to the secure element (few local electromagnetic side-channel acquisitions, i.e. few minutes, are enough) in order to extract the ECDSA secret key. In the case of the FIDO protocol, this allows to create a clone of the FIDO device.
All YubiKey 5 Series (with firmware version below 5.7) are impacted by the attack and in fact all Infineon security microcontrollers (including TPMs) that run the Infineon cryptographic library (as far as we know, any existing version) are vulnerable to the attack.
https://www.yubico.com/support/security-advisories/ysa-2024-03/
-
New research reveals timing side channels can leak ChatGPT prompts, exposing confidential info through subtle delays. AI security needs to consider more than just inputs.
Read more: https://dl.acm.org/doi/10.1145/3714464
#AIsecurity #SideChannel #LLM -
Безопасности не существует: как NSA взламывает ваши секреты
Конечные поля, хэш-мясорубки, скрытые радиоканалы и трояны, запаянные в кремний. Пока мы гордимся замками AES-256, спецслужбы ищут обходные тропы: подменяют генераторы случайности, слушают писк катушек ноутбука и вывозят ключи через незаметные ICMP-пакеты. Эта статья собирает мозаичную картину современных атак — от математических лазеек до физических побочных каналов — и задаёт неудобный вопрос: существует ли вообще абсолютная безопасность? Если уверены, что да, проверьте, не трещит ли ваш щит по швам.
https://habr.com/ru/articles/918068/
#криптография #безопасность #NSA #шифрование #конечные_поля #sidechannel #аппаратные_бэкдоры #генератор_случайности #covert_channels #киберпанк
-
TOR is not a gimmick, but it doesn’t claim to be perfect either.
#sidechannel #COSADE #TorProject
A mask is still the best metaphor.
https://yashalevine.com/surveillance-valley
#MIC #MilitaryIndustrialComplex #ChrisHedges #SI #Scheer #Surveillance #Privacy #CivilSociety #MartialLaw #Junta #Tech #CS
#History #MIC #Arpa #ONR
#clock #delusion #psy #genocidalSpyime #Pharoh
The hate group violates our privates with subconscious patrols . . . -
SCA4PQC – die @Cyberagentur startet ein Forschungsprogramm zur Entwicklung seitenkanalresistenter Post-Quanten-Kryptographie. Ziel: Schutz vor Quantenangriffen und physischen Seitenkanalangriffen. Fokus: Cloud/Desktops, IoT und Smartcards. Forschung und Wirtschaft sind eingeladen.
Mehr Informationen: https://t1p.de/b52np
#PostQuantum #CyberSecurity #SCA4PQC #PostQuantumCrypto #SideChannel #ITSecurity #OpenScience