Sliding right into disaster: Left-to-right sliding windows leak
eprint.iacr.org
eprint.iacr.org
Although the researchers describe mitigations that will dramatically reduce the information leakage, this is further evidence that it's quite dangerous to do software crypto on hardware that may be shared with an adversary.
I'd generalise and replace "software crypto" with "anything". Especially with things like https://en.wikipedia.org/wiki/Row_hammer
Especially since they usually fit both those shoes.
Take stuff like that as a possibly helpful nudge in the right direction, not the one and only truth, regardless of who may have said it.
I'm not looking to either discount or treat as axiomatic anyone's arguments based on their apparent position along some authority gradient, if that's what you are getting at. What would be the point?
Of course, SGX is not quite available yet on server class CPUs.
It appears a runtime per-site-per-use license is required though.
[0] http://www.sharcs-project.eu/m/documents/papers/a02-gotzfrie...
Wouldn't your statement imply that we should not be terminating TLS on AWS nodes? Is it even practical these days to not use cloud based, shared hardware?
Again, RSA 1024, we've known that's weak for a while now...
This is the fix: https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=c...
Make sure you do fixed computation regardless of data involved. This involves slowing things down and making sure the CPU/compiler does not optimize anything so things become unbalanced.
Straightforward way to make this constant time is to do the multiplication always and discard the result for 0 bits.
Motivation of the sliding window algoritms is that they are faster and also believed to be "more constant time" than the straightforward square and multiply.
The paper's title is: "Sliding right into disaster: Left-to-right sliding windows leak". Standard HN practice is to use the page's title as the post title.
Alternative options that seem clear to me:
- "Local-machine side channel attack defeats RSA-1024 decryption using GPG (CVE-2017-7526)"
- "Complete break of RSA-1024 in GPG (CVE-2017-7526) for local attackers"
- "Sliding right into disaster: Left-to-right sliding window attack against local-machine RSA-1024 in GPG (CVE-2017-7526)"
Thanks!
I was actually disappointed!