New CPU vulnerability but this time it's Apple: GoFetch -
Breaking Constant-Time Cryptographic Implementations Using Data Memory-Dependent Prefetchers
GoFetch is a microarchitectural side-channel attack that can extract secret keys from constant-time cryptographic implementations via data memory-dependent prefetchers (DMPs).
Website:
https://gofetch.fail/
Direct link to paper:
https://gofetch.fail/files/gofetch.pdf
@76148920 Thanks to @5cc922aa calling out the @5dc88666 for many years over on the Birdsite, I was somewhat aware that it’s not all peachy there. e.g. They making millions in marketing stuff and these funds are then not actually given to opensource projects.
https://x.com/jessfraz/status/1681475908186832896
Notes by 685060d7 | export