04:58 pm, 11 Jun 06

cryptography is depressing

Cache Attacks and Countermeasures: the Case of AES:
We describe several software side-channel attacks based on inter-process leakage through the sate of the CPU's memory cache. [...] experimentally demonstrate their applicability to real systems, such as OpenSSL and Linux's dm-crypt encrypted partitions (in the latter case, the full key can be recovered after just 800 writes to the partition, taking 65 milliseconds).
(Previously [heh, tags eventually came, but not as we had hoped].)