Hyper-Threading Considered Harmful

Post Reply
Derek
Site Admin
Posts: 2489
Joined: Tue Jul 23, 2002 3:55 pm
Location: Canada
Contact:

Hyper-Threading Considered Harmful

Post by Derek »

Hyper-Threading, as currently implemented on Intel Pentium Extreme Edition, Pentium 4, Mobile Pentium 4, and Xeon processors, suffers from a serious security flaw. This flaw permits local information disclosure, including allowing an unprivileged user to steal an RSA private key being used on the same machine. Administrators of multi-user systems are strongly advised to take action to disable Hyper-Threading immediately; single-user systems (i.e., desktop computers) are not affected.
Interesting to say the least!

Website: http://www.daemonology.net/hyperthreadi ... d-harmful/

To read his paper, go here: http://www.daemonology.net/papers/htt.pdf

Derek
-Derek
24seven
IRC Lurker
Posts: 495
Joined: Wed Jul 24, 2002 5:23 pm
Location: Derbyshire UK
Contact:

Post by 24seven »

duraid @ 2cpu.com wrote:This is not a problem specific to Intel hyperthreading. The situation occurs on any processor that allows multiple concurrent threads of execution that can "attack" a shared cache. Therefore, the same problem will be observed on:

any multi-core processor that has a shared cache, regardless of whether or not it has any sort of hyperthreading. For example, IBM's POWER4 and POWER5 are vulnerable to the attack described, even if you disable SMT.
Read the thread here
Post Reply