netcat security flaw

By: jouni osmala (my.name.delete@this.aalto.fi), September 12, 2019 10:22 pm
Room: Moderated Discussions
Latest Intel CPU vulnerability called netcat, that blasts Intel direct to cache IO seems to me more like a software security flaw that gets exposed in target machine. They use the LLC cache side channel to figure out timing of network packets bringing keyboard presses and deduce what is typed in. I'm just curious why this timing data couldn't be leaked by malicious router between host and client, and if that is the case why it is considered a hardware security flaw instead of software security flaw.
 Next Post in Thread >
TopicPosted ByDate
netcat security flawjouni osmala2019/09/12 10:22 PM
  netcat security flawAdrian2019/09/13 12:04 AM
    netcat security flawaaron spink2019/09/13 04:09 AM
      netcat security flawFoo_2019/09/13 05:26 AM
        netcat security flawMontaray Jack2019/09/13 11:51 AM
          netcat security flawMontaray Jack2019/09/13 12:15 PM
            netcat security flawAdrian2019/09/13 12:36 PM
              netcat security flawMontaray Jack2019/09/13 01:17 PM
          netcat security flawrwessel2019/09/13 06:10 PM
            netcat security flawanon2019/09/13 06:40 PM
              netcat security flawaaron spink2019/09/14 01:18 AM
            netcat security flawMontaray Jack2019/09/14 12:09 PM
              netcat security flawMichael S2019/09/16 01:14 AM
                netcat security flawMontaray Jack2019/09/17 07:35 PM
                  netcat security flawDavid Hess2019/09/18 08:23 AM
                    netcat security flawMontaray Jack2019/09/18 08:55 AM
                      netcat security flawDavid Hess2019/09/18 12:09 PM
        netcat security flawaaron spink2019/09/14 01:13 AM
          netcat security flawFoo_2019/09/14 10:13 AM
            netcat security flawMichael S2019/09/15 02:05 AM
              netcat security flawaaron spink2019/09/15 02:42 AM
              netcat security flawJouni Matti2019/09/17 08:04 PM
                netcat security flawMichael S2019/09/18 03:05 AM
                  netcat security flawKonrad Schwarz2019/09/18 07:40 AM
            netcat security flawaaron spink2019/09/15 02:41 AM
      user errorshobold2019/09/15 02:04 AM
        user errorsaaron spink2019/09/15 02:47 AM
          user errorshobold2019/09/15 03:57 AM
            user errorsMontaray Jack2019/09/15 03:19 PM
              dumb is betterMichael S2019/09/16 01:01 AM
            user errorsMontaray Jack2019/09/15 04:38 PM
              user errorsGabriele Svelto2019/09/15 11:54 PM
            user errorsanon2019/09/15 05:36 PM
            user errorsaaron spink2019/09/15 10:36 PM
              user errorshobold2019/09/16 09:30 AM
                user errorsGabriele Svelto2019/09/16 11:13 AM
                  user errorshobold2019/09/16 11:39 AM
                    user errorsMichael S2019/09/16 12:19 PM
                    user errorsaaron spink2019/09/16 04:24 PM
                      user errorsanonymou52019/09/16 06:34 PM
                        user errorsanon2019/09/16 08:24 PM
                user errorsaaron spink2019/09/16 11:47 AM
                  user errorsMichael S2019/09/16 12:11 PM
Reply to this Topic
Name:
Email:
Topic:
Body: No Text
How do you spell purple?