Live data from Hacker News

Take a Way: Exploring the Security Implications of AMD’s Cache Way Predictors [pdf]

mlq.me

1–10 of 22 posts

Re: Take a Way: Exploring the Security Implications of AMD’s Cache Way Predictors [pdf]

#4

This is dated June 2020?

It’s for a conference that’s in June.

What’s the story here?

Conference papers are typically published by the conference months after the conference so that they’re vetted, reviewed, and cleaned up.

Re: Take a Way: Exploring the Security Implications of AMD’s Cache Way Predictors [pdf]

#5

Earlier quoted context omitted.

It’s for a conference that’s in June.

What’s the story here? Conference papers are typically published by the conference months after the conference so that they’re vetted, reviewed, and cleaned up.

Preprints are a pretty common thing.

Re: Take a Way: Exploring the Security Implications of AMD’s Cache Way Predictors [pdf]

#6

Earlier quoted context omitted.

It’s for a conference that’s in June.

What’s the story here? Conference papers are typically published by the conference months after the conference so that they’re vetted, reviewed, and cleaned up.

Traditionally, conference proceedings are given out at the conference itself.

Looking at the conference in question (ASIACCS'20), the camera-ready deadline for a paper is March 15. Most authors probably have that camera-ready version at this point.

Re: Take a Way: Exploring the Security Implications of AMD’s Cache Way Predictors [pdf]

#7
post #6

Earlier quoted context omitted.

What’s the story here? Conference papers are typically published by the conference months after the conference so that they’re vetted, reviewed, and cleaned up.

Traditionally, conference proceedings are given out at the conference itself. Looking at the conference in question (ASIACCS'20), the camera-ready deadline for a paper is March 15. Most authors probably have that camera-ready version at this point.

This could just be SOP for these authors, but it's also possible they are worried that the conference will be cancelled, as have so many others. Perhaps they figuratively blurted out their material.

Re: Take a Way: Exploring the Security Implications of AMD’s Cache Way Predictors [pdf]

#8
post #7
post #6

Earlier quoted context omitted.

Traditionally, conference proceedings are given out at the conference itself. Looking at the conference in question (ASIACCS'20), the camera-ready deadline for a paper is March 15. Most authors probably have that camera-ready version at this point.

This could just be SOP for these authors, but it's also possible they are worried that the conference will be cancelled, as have so many others. Perhaps they figuratively blurted out their material.

The conference is already postponed to October: https://asiaccs2020.cs.nthu.edu.tw/conference-postponed/

Re: Take a Way: Exploring the Security Implications of AMD’s Cache Way Predictors [pdf]

#9
post #8
post #7

Earlier quoted context omitted.

This could just be SOP for these authors, but it's also possible they are worried that the conference will be cancelled, as have so many others. Perhaps they figuratively blurted out their material.

The conference is already postponed to October: https://asiaccs2020.cs.nthu.edu.tw/conference-postponed/

Well, there ya go. You can't wait 4 extra months to break a story. Someone else will beat you to it.

Re: Take a Way: Exploring the Security Implications of AMD’s Cache Way Predictors [pdf]

#10
AMD's response (https://www.amd.com/en/corporate/product-security):

"Take A Way 3/7/20

We are aware of a new white paper that claims potential security exploits in AMD CPUs, whereby a malicious actor could manipulate a cache-related feature to potentially transmit user data in an unintended way. The researchers then pair this data path with known and mitigated software or speculative execution side channel vulnerabilities. AMD believes these are not new speculation-based attacks.

AMD continues to recommend the following best practices to help mitigate against side-channel issues:

Keeping your operating system up-to-date by operating at the latest version revisions of platform software and firmware, which include existing mitigations for speculation-based vulnerabilities

Following secure coding methodologies

Implementing the latest patched versions of critical libraries, including those susceptible to side channel attacks

Utilizing safe computer practices and running antivirus software"

Post reply on HN