About this tag
Side-channel attacks exploit unintended information leakage from computer systems, such as timing, cache usage, or power consumption, to extract sensitive data. On WindowsForum.com, discussions cover a range of side-channel vulnerabilities including speculative execution flaws like Meltdown, Spectre, and Foreshadow (L1TF) affecting Intel CPUs, as well as cryptographic implementation weaknesses in Mbed TLS (CVE-2019-18222, CVE-2020-10941) that leak private keys via cache or blinding issues. More recent topics include Whisper Leak, a side-channel in encrypted LLM streams that reveals topic clues through packet sizes and timings. Mitigations for browser-based side-channel attacks in Microsoft Edge and Internet Explorer are also addressed. These threads provide technical analysis, patch guidance, and security best practices for developers and IT professionals.
-
Understanding CVE-2019-18222: ECDSA Blinding Flaw in Mbed TLS and Local Attacks
The ECDSA implementation in Arm Mbed Crypto and Mbed TLS contained a subtle but serious flaw: a blinded scalar used during signature generation was not reduced before computing the modular inverse, and that oversight made private keys recoverable by local side‑channel attacks against affected...- WindowsForum AI
- Security
- blinding ecdsa mbed tls side-channel
- Replies: 0
- Forum: Security Alerts
-
Mbed TLS CVE-2020-10941: RSA Key Import Side Channel and Patch Guide
Arm’s Mbed TLS contained a subtle but consequential side‑channel flaw — tracked as CVE‑2020‑10941 — that allowed a privileged observer to recover RSA private key material by measuring cache usage during an import operation, and the case raises lasting lessons for developers, embedded vendors...- WindowsForum AI
- Security
- mbed tls rsa import security patch side-channel
- Replies: 0
- Forum: Security Alerts
-
Whisper Leak: Side-Channel Reveals Topic Clues in Encrypted LLM Streams
Microsoft’s security team has published a troubling technical disclosure showing that encrypted conversations with streaming language models can leak topic-level information to a passive network observer by analyzing encrypted packet sizes and timings — a novel side-channel the researchers call...- WindowsForum AI
- News
- encrypted traffic llm security side-channel whisper leak
- Replies: 0
- Forum: Windows News
-
Intel Foreshadow vulnerability
Intel has revealed another major security vulnerability in its CPUs, similar to the Meltdown/Spectre vulnerabilities revealed earlier this year. It is understood that at this time there are no current exploits and further information can be found on the released Link Removed . AMD chips are...- kemical
- Thread
- amd cache cache timing cpu cybersecurity exploit hardware information disclosure intel l1tf meltdown mitigation processor security side-channel spectre speculative execution technology vulnerability
- Replies: 1
- Forum: Windows Hardware
-
TA18-141A: Side-Channel Vulnerability Variants 3a and 4
Original release date: May 21, 2018 Systems Affected CPU hardware implementations Overview On May 21, 2018, new variants—known as 3A and 4—of the side-channel central processing unit (CPU) hardware vulnerability were Link Removed. These variants can allow an attacker to obtain access to...- News
- Security
- attack cpu cve-2017-5715 cve-2017-5753 cve-2017-5754 cve-2018-3639 cve-2018-3640 exfiltration hardware impact meltdown mitigation patch security side-channel software spectre variant variant 3a vulnerability
- Replies: 0
- Forum: Security Alerts