Basically is RSA so vulnerable to sidechannels that we can only use it safetly inside HSMs?
I bet this would be much harder to do for ECC.
I bet this would be much harder to do for ECC.
So, ECC implementations are not generally in a better state than RSA.
This is why curve25519 and its ilk are so much better; they can be efficiently implemented using the Montgomery ladder which is really very easy and cheap to make free of side-channels.
Unfortunately these attacks all focus on implementation issues rather than the underlying algorithms (hence the name).