@duke_cpu My guess is that that lone via is an alignment marker. Are there any other, perhaps forming a matrix? Mask alignment in the era of the 4004 was likely done by hand using a microscope, so a lone via like that could have been used to set mask alignment.
@duke_cpu Thanks, I am busy gathering a group of reverse engineering and silicon Trojan detection specialists that can help with extracting the circuit netlist. Since the 8008 looks to be a single metal layer with metal-over-poly crossings, extraction should be a snap!
Q: Can we get the attack code? The PoC code is currently in responsible disclosure with the Rust developers. Once that period ends, we will release the attack code. This attack PoC was created by Christopher Felix, Donayam Benti, and Todd Austin.
We've released a video of our Spectre V1 attack performing arbitrary buffer overreads on safe Rust code, plus a short tutorial on how the attack works. You can watch the attack demo here: https://t.co/2mMpeu5XXm
Q: Should we be worried? This PoC would only be a risk in a few situations. If you bring 3rd-party Rust code into your address space (e.g., safe Rust drivers in the Linux kernel), this attack will allow the 3rd-party safe Rust code to arbitrarily access all of reachable memory.
In Rust We Trust?!?! We now have a working Spectre V1 attack for Rust. Using our Spectre V1 transient execution attack, we are able to force a bounds-checked Rust array to perform an arbitrary buffer overread. I've attached the function that we are attacking with Spectre V1.
This proof of concept attack was built by Christopher Felix, Donayam Benti, and me (all from University of Michigan CSE). The attack demo is running on a 13th-gen Core i7-13700H on Ubuntu 20.04 inside VirtualBox 7.0 on Windows 11. Built with rustc compiler version 1.73.0.
A new paper from my research group on Sequestered Encryption (SE). This is work by PhD student Lauren Biernacki, who is on the job market. SE transforms a TEE into one with cryptographic-strength confidentiality defenses.
Read the paper here: https://t.co/Pk8gMSdj8x
Are you a student delving into research for the first time? If so, please check out my talk on the "Zen of Research". This is a guide for new researchers as they take that exciting (and often scary) first step into the world of research.
https://t.co/8Ril39fQCo
You can meet the AURA 2022 students here: https://t.co/e09tJUWybD
And, you can see their research projects here: https://t.co/7X8kBoeZDj
Special thanks to our sponsors: Google, Intel, ARM and Michigan Engineering!
Last Friday, I had the pleasure of attending the AURA 2022 Student final presentations. AURA is the African Undergraduate Research Adventure, which brings top African undergrads to UM for an embedded summer research experience. AURA website is here: https://t.co/jAQRkOFqVv
TrustForge implements a hardware security technology called Sequestered Encryption, which builds crypto wall between sensitive data and all software. You can learn more at https://t.co/D2YJjapv6H. Or DM me!
I have always wanted to bring new technology to the market -- well, that day has arrived! Agita Labs released TrustForge, which implements secure computation for Azure. Secure computation is always encrypted, thus it is not vulnerable to software hacking.
https://t.co/JIncSebLPU