Blog | G5 Cyber Security

New PortSmash Hyper-Threading CPU Vuln Can Steal Decryption Keys

A new side-channel vulnerability has been discovered called PortSmash that uses a timing attack that to steal information from other processes running in the same CPU core with SMT/hyper-threading enabled. Using this attack, researchers were able to steal the private decryption key from an OpenSSL thread. The vulnerability was discovered by researchers Billy Bob Brumley, Cesar Pereida Garcia, Sohaib ul Hassan, and Nicola Tuveri from the Tampere University of Technology in Finland.

Source: https://www.bleepingcomputer.com/news/security/new-portsmash-hyper-threading-cpu-vuln-can-steal-decryption-keys/

Exit mobile version