Unable to load image

Hertzbleed Attack: New CPU Vulnerability

https://www.hertzbleed.com

tl:dr I'm to r-slurred to understand this but you will probably be affected by this

Orange forum

52
Jump in the discussion.

No email address required.

this can easily be fixed by locking the core frequency for the duration of sensitive cryptographic calculations

Jump in the discussion.

No email address required.

easier said than done, hurts performance too

Jump in the discussion.

No email address required.

you can force speed boost on for those moments and get the same security fix

Jump in the discussion.

No email address required.

the whole reason the dynamic scaling exists is that the cpu often cannot remain at the maximum clock speed forever, often for heat reasons

Jump in the discussion.

No email address required.

it's only for the duration of the decryption calculation just lock for a short burst, not at all times, and only on that physical core.

at worst it would mildly degrade effectiveness of dynamic scaling wasting some power/heat

Jump in the discussion.

No email address required.

There's already stuff in place for protected memory. You can just assume that whenever those syscalls get run that they want to run in a stable frequency

Jump in the discussion.

No email address required.

shut up nerd

Jump in the discussion.

No email address required.

![](https://media.giphy.com/media/3zpHYzhLV3ZzW/giphy.webp)

Jump in the discussion.

No email address required.

Wouldn't adding random delays work too?

Jump in the discussion.

No email address required.

that would hurt performance a lot worse than telling the CPU to "finish this calculation before you speed step again"

Jump in the discussion.

No email address required.

depends tbh, 1 or 2 nanoseconds should do it well enough?

Jump in the discussion.

No email address required.

maintaining a supply of sufficiently random data for padding is somewhat costly

Jump in the discussion.

No email address required.

Link copied to clipboard
Action successful!
Error, please refresh the page and try again.