
Attacking CPUs with Power Side Channels from Software: Warum leaked hier Strom? (en) (rc3)
Chaos Computer Club - archive feed · Moritz Lipp, Michael Schwarz, Daniel Gruss, Andreas Kogler
December 28, 202059m 16s
Audio is streamed directly from the publisher (cdn.media.ccc.de) as published in their RSS feed. Play Podcasts does not host this file. Rights-holders can request removal through the copyright & takedown page.
Show Notes
Everyone knows and loves the famous line from the cinematic masterpiece where the IT-Security specialist asks the CPU architect: "Warum leaked hier Strom?" (Why is power leaking here?).
In this talk, we want to answer that question. We demonstrate how we can attack modern processors purely in software, relying on techniques from classical power side-channel attacks. We explain how we abuse the unprivileged access to energy-monitoring features of modern Intel and AMD CPUs. With PLATYPUS, we show how to steal cryptographic keys from the operating system or trusted-execution environments, and how to break kernel address-space layout randomization within seconds. Finally, we discuss the mitigations that prevent our attacks.
about this event: https://fahrplan.events.ccc.de/rc3/2020/Fahrplan/events/11404.html
Topics
rc3-mcr114042020IT-Securitymain