Rain: Cloud Leakage via Hardware Vulnerabilities – Vusec
vusec.net·9h·
Discuss: Hacker News
Flag this post

The discovery of Spectre and Meltdown in 2017 marked the first instances of “transient execution vulnerabilities”. These are vulnerabilities in the internal design of CPUs (their “microarchitecture”), which attackers may abuse to steal data. Examples may include one smartphone app stealing data from other apps or the operating system, or a website stealing data from another website open in the same browser.

After eight years of research, the security community is still doubtful to what extent these transient execution vulnerabilities pose serious security threats in real-world scenarios. Understanding the nature and root cause of these vulnerabilities requires expert knowledge of computer architecture and (low-level) software. Moreover, exploiting these vulnerabilities requires v…

Similar Posts

Loading similar posts...