The attack is against the RSA implementation specifically. Is there a gpg asymmetric encryption that would be considered safe? If not, is there a reasonable gpg alternative?
The attack is against the RSA implementation specifically. Is there a gpg asymmetric encryption that would be considered safe? If not, is there a reasonable gpg alternative?
GnuPG 1.4.14 released
What's New
===========
* Mitigate the Yarom/Falkner flush+reload side-channel attack on
RSA secret keys. See http://eprint.iacr.org/2013/448
Edit: and Libgcrypt 1.5.3 contains fix for GnuPG 2.x"Furthermore, as virtual machine hypervisors transparently share memory pages between VMs [5,19], the attack is applicable across the isolation layer between VMs"
It's saying your VMs aren't safe - your Amazon/Linode/Rackspace/DigitalOcean/NineFold/Hertzner cloud instances _do_ have arbitrary users running arbitrary code on them – and the hypervisor can't protect you against what they do (in terms of manipulating the shared cache).
There have been cache side-channels demonstrated against some AES implementations, but this attack requires some bit of code whose "execution-or-not" (for lack of a better term) reveals some information the user would like to keep secret.
It is actually very worrying, since it might affect compression software (leak info about the file being compressed), text editors and other software that executes code based on key presses (cross-user keylogger), code whose execution depends on mouse actions e.g. button hover/click events (track another user's mouse), and so on.
Essentially, it turns all "if", "while", and "for" statements into information leaks.
I've written more about it here:
What is to stop creating a statically linked build of GPG, create a new user account, chmod 0700 the new uid's homedir, copy the new binary into the private user account, and perform all your encryption work in there.
So long as you're not running on a VM using tech like kernel samepage merging, pages from the binary should never be shared