More interposer fun, this time with DDR5 memory. Breaking TDX, SGX, SEV and even Nvidia TEEs. Checkout our work at https://t.co/Jl1dpGnM6J, and get a personally-signed Intel attestation report at @TEEdotFail.
Want to know what happens when commercial TEEs meet improvised DRAM memory interposers? SGX mayhem including attestation key extraction. Please DO try that at home😉. Check out our work at https://t.co/JyvHP48nez
Embarking on a new project that needs physical access to an H100 GPU. Any chance anyone is willing to let us borrow one (we promise to return it), in exchange for a security exploration into the land of confidential computing? If so, DM me for further details. Thanks :)
After the Satoshi grace period, the FC'25 deadline has been set to 11 October, 2024 (AoE). This is a firm deadline! Good luck preparing your submissions!
A great summary of the Zerocash/Zcash origin story. Truly humbled and grateful to have been a part of this, and appreciative of IEEE S&P for the recognition.
Zerocash won the 2024 IEEE S&P Test of Time Award. Published in 2014, it pioneered using zkSNARKs for blockchains. Its techniques ended up in Zcash, Tornado Cash, Railgun, and other deployed protocols for private payment on public blockchains. It started with last years winner...
The Zerocash paper has won a Test of Time award from @IEEEorg to recognize its substantial, lasting, broad, and currently relevant impact on computer science.
Excited to present "Pathfinder: High-Resolution Control-Flow Attacks Exploiting the Conditional Branch Predictor" at @ASPLOSConf with Archit Agarwal, Max Christman, @CryptoGPS, @DanielGenkin, Andrew Kwong, @flowyroll, @deiandelmars, @mktaram and Dean Tullsen. (1/4)🧵
Congrats to my co-authors Eran Tromer, @secparam, Christina Garman, @MadarsV, Allesandro Chiesa, @EliBenSasson for winning a “test of time” award at IEEE S&P for Zerocash!
Congrats to @arushi1250 for successfully defending her PhD today! (My first student!) If you haven't seen it, checkout her great work on improving the security/privacy of Tor with our Bento architecture. Very proud of the work she's done and great things she'll do in the future!
Apply to attend GREPSEC VI! USENIX is hosting the sixth GREPSEC workshop on August 8, 2023 in Anaheim, CA, co-located with USENIX Security '23 and SOUPS 2023. Applications are due May 24: https://t.co/faj6707HI4 #usesec23#soups2023@SOUPSConference
GREPSEC workshop for women and underrepresented grad students in S&P is back, live and in person, colocated with #usesec2023! Applications are due May 22, please help us spread the word! https://t.co/vLx7mLBI22
@SecretShahar 👍 Yes definitely check out the post from Secret Network as well where they discuss both their response and mitigations for the vulnerability we reported, as well as planned future work.
Excited to finally release the paper we've been working on that explores the challenges of using SGX for real world applications! tl;dr, it's very hard, post-compromise recovery is hard, and we can leak secrets. Also a great resource for learning about SGX attacks and defenses!
Our survey of SGX attacks is out! Come learn about how SGX fails in real life. Check out our website https://t.co/JTAGNGuHld including attacks on @SecretNetwork and @CyberLink PowerDVD.
Our survey of SGX attacks is out! Come learn about how SGX fails in real life. Check out our website https://t.co/JTAGNGuHld including attacks on @SecretNetwork and @CyberLink PowerDVD.
Excited to announce that registration is open for GREPSEC V -- a workshop for early-stage grad students doing research in security and privacy who come from underrepresented populations. Women/NB/gender minorities, BIPOC, LGBTQ+, etc.
https://t.co/IDoCs0a7Sh
Huge congratulations to @HexHiveEPFL's @amipri@PurdueCS for passing her defense today. You may know her from fun work on finding unsafe variadic function calls, type safety violations for C++ applications or tightening the bounds for CFI!
Congrats to my student Stephen Herwig for making the paper he led “Achieving Keyless CDNs with Conclaves” reproducible! Conclaves are containers of enclaves, allowing legacy apps (even multi-process with shared memory) to be deployed in secure enclaves. Joint work with @CryptoGPS
USENIX Security still has a few open slots for Lightning Talks! Please signup and help make this already great session even better! There will be prizes...
https://t.co/MpzfoodD9R