Fine grain Cross-VM Attacks on Xen and VMware are possible
eprint.iacr.org
eprint.iacr.org
- Flush+Reload: a High Resolution, Low Noise, L3 Cache Side-Channel Attack http://eprint.iacr.org/2013/448
- Cross-VM Side Channels and Their Use to Extract Private Keys https://www.cs.unc.edu/~reiter/papers/2012/CCS.pdf
Side-channels on the web are more and more present. Non-functional behaviors carry too much information if proper countermeasures are not embedded in the design of some features. For instance with autocomplete features, it is possible to know what is being typed by someone even over HTTPS by looking at the packet traffic due to autocompletion:
- Keystroke Timing Analysis of on-the-fly Web Apps http://flyer.sis.smu.edu.sg/acns13-2.pdf
- Implementing side-channel attacks on suggest boxes in web applications http://dl.acm.org/citation.cfm?id=2490436 (did not find the PDF online for free -_-, EDIT: The file happens to be available here: http://www.fileswap.com/dl/FTYVPFkN5/ :-°)
- Some slides: http://people.cse.nitc.ac.in/kartik/files/k4rtik-csu491-semi...
I think that while a bit scary, this is quite interesting.
Does anyone know if AES is particularly susceptible to these side-channel attacks? Are the Bernstein constructs in NaCl safer because of being easier to implement in constant time?
Edit: Apparently NaCl even includes a constant time AES implementation[1] so it would be nice to have seen it compared in this paper.
Because when you have branches, even if they are perfectly balanced in time (i.e., number of instructions), it is still possible to attack on recent processors with pipelines (like in smartphones for instance), because the processor will start computing the more probable branch in advance (and if you know how it works you can compute which branch that is) and then it will actually be faster if it is actually this branch that is taken than if it is the other. It's a bit like cache timing attacks, but with code instead of data.
Instead of hoping everyone writes constant-time code are Intel/AMD working on virtualization extensions to fix these? Maybe allowing high-end CPUs to partition their cache/TLBs/BPUs per virtual host and virtualizing the instruction pointer and other cross-VM leaks.
I would be very, very careful before saying that. Actually I wouldn't even say it. Hardware implementation are also subject to side-channels, even when they include countermeasures. Leakage models we have for hardware are not accurate enough, and maybe they can't be. Take for instance with the power consumption side-channel: not every bit in a register leak the same (when being set or reset, they do not consume the same amount of energy / emit the same amount of EM radiation), and the actual leak depends on so many thing that the only way to know it is to measure it in the precise environment of the threat on the actual hardware that may be subject to attack. Actual hardware behavior is so difficult to predict, and side-channel attacks manage to exploit any bias, leak, glitch, anything.
Plus, there is still the possibility of fault injection attacks…
Edit: I wonder if similar timing attacks can be used against the VMs of scripting languages to recover code. It would be a neat hack.
Public services could make it easier to make sure you have a whole host for yourself. I can imagine even small sites wanting to make sure that the machines doing SSL termination aren't co-hosted with anyone else.
You shouldn't view any sort of security measure as perfect, but that doesn't mean that using good practices doesn't contribute to better safety.
Using your example: attackers being reduced to performing side channel attacks after owning a VM is better than them having direct access to the host machine itself (using the same exploit), even if it's still a security flaw.
Defense in depth is a good idea, even if it's not perfect. (Note that your argument goes from "not entirely safe" to "not safer", which doesn't logically follow.)
basically, like anything else in life, its about.. balance.
vm provide a good balance for most things. if you're holding the fate of the world tho, please dont store it in AWS - Thanks. :p
Doesn't even require a VM.
They're in the middle of fscking up OpenSSL as we write.
There couldn't possibly be any companies in the world running multiple VMs on hardware they solely use (either owned or rented).
I am not clear on what to do here. I don't knowingly use AES anywhere; does using bcrypt/scrypt for my PW hashing help at all or is that unrelated?