Negative Result: Reading Kernel Memory from User Mode
cyber.wtf
cyber.wtf
This basically adds another set of tools to the architectural-level attack toolbox. From reading this I expect we'll see some interesting developments in the future.
1. It's a storage channel when one process can write to it and another can read it. The temporary storage folders that are world-writable was one example. Another was TCP/IP headers. Memory that wasn't zeroed after use is another.
2. It's a timing channel when it can affect how long a process containing secrets takes to do something and that timing is visible to a process wanting the secrets. Network jitter, hard disk arms, caches, and Intel HT have all been used as timing channels. If it could be visibly timed & noise canceled out enough, then speculative and OoO execution might be another. Worth looking into.
These aren't adding tools, though. They've always been there. People just don't do covert, channel analyses. They even call requirements like that "bureaucratic, red tape with no value for security." Then, rediscover them piece by piece later while still ignoring the prior work. ;)
Which means that basically any instruction dependent on the load has to wait until after the access check passes. No value available means that no further speculation (e.g. using that value to issue further value-dependent loads).