Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Side channel attacks always strike me as the coolest.

How practicable is this? You've got to be on the same physical machine for this to work. Is that easily engineered for, say, EC2? Even if you can't control whether on you're the same machine, is it possible to get any information on the VMs that you're sharing it with?



I don't know how things are today, but in 2009 it was possible. See, for instance, the paper Hey, You, Get Off of My Cloud: Exploring Information Leakage in Third-Party Compute Clouds at http://cseweb.ucsd.edu/~hovav/dist/cloudsec.pdf

From the abstract: Using the Amazon EC2 service as a case study, we show that it is possible to map the internal cloud infrastructure, identify where a particular target VM is likely to reside, and then instantiate new VMs until one is placed co-resident with the target. We explore how such placement can then be used to mount cross-VM side-channel attacks to extract information from a target VM on the same machine. Scared yet?


a) You have to be on the same machine, and it is probably most effective if you are on the same core, since it is a cache-based probe. If the attacker does not share the same cache as the victim, this attack will not work.

b) If there are more that just the attacker and the victim on the same machine (core), it is very likely to add a lot of noise to the side channel (attack) signal since it will be busy "dirtying" the cache that the side channel attack is being carried out on. Very likely this will prevent the attack from being successful.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: