Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Thu, 21 Jun 2018 10:37:54 +0100
From: Stuart Henderson <stu@...cehopper.org>
To: oss-security@...ts.openwall.com
Cc: secure@...el.com
Subject: Re: Intel hyper-threading security issues

On 2018/06/21 07:56, Georgi Guninski wrote:
> On Wed, Jun 20, 2018 at 12:48:55AM +0400, Loganaden Velvindron wrote:
> > Hi all,
> > 
> > OpenBSD has gone ahead and disabled Intel Hyper threading with a
> > fairly detailed comment about the reasons behind:
> > 
> > https://www.mail-archive.com/source-changes@openbsd.org/msg99141.html
> >
> 
> Freebsd:
> 
> https://www.freebsd.org/security/advisories/FreeBSD-SA-05:09.htt.asc
> Topic:          information disclosure when using HTT
> Announced:      2005-05-13
> When running on processors supporting Hyper-Threading Technology, it is
> possible for a malicious thread to monitor the execution of another
> thread.
> V.   Solution
> 
> Disable Hyper-Threading Technology on processors that support it.

That isn't possible with some BIOS. For example, newer Lenovo machines
removed the option apparently due to perceived lack of demand...

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.