Very exciting to see the @ETH_en president, @Joel_Mesot, talk about our work at the Swiss Cyber Security Days 2024 🚀+Phone (https://t.co/Nqr7gxnAaY) is based on TEEtime: an open and secure smartphone architecture without compromises in functionality @shw3ta_shinde @SrdjanCapkun
As a first step, we have built TEEtime.
Users can now run secure apps in a domain that is not controlled by the OS, without trading off the protections provided by OS vendors. Win-win!
Joint work with a fantastic team @SrdjanCapkun @dn0sar@Mark_Ku96
Paper https://t.co/jRMvILRuOJ
In our paper to appear @USENIXSecurity 21, we observe that when frequently issuing interrupts, instructions execution times correlate with their virtual address (mod 16). We used this to exploit SGX enclaves. \w Moritz Schneider @M__Haller @SrdjanCapkun
https://t.co/MJ14SzaF06
The effect is more noticeable with memory writes: e.g. a memory write instruction at address 0x6 tends to execute slower than one at 0xe (mod 16), with the difference being up to 100 cycles on average, as shown below in a figure from our proof-of-concept.
https://t.co/vTvTVI0YJO
@kennwhite@USENIXSecurity We used our attack to exploit the mbedTLS and the Intel IPP cryptography library. We only tested the defense on OpenSSL, but not the attack. We did not notice this error on the conclusion until now, but we are updating the version on arXiv to fix this.
Intel are disclosing 77 vulns today (https://t.co/5o4kjTPLp5), some in their CPUs - HW bugs are always painful, but hardware is never perfect. Happy to see TAA disclosed after I found it >1y ago, but @dkg0414's page size issue looks a lot more painful. JCC icache errata too.
After enough hours of sleep it's time to announce that we got the 5th place at @oooverflow#DEFCON CTF as the best European team! Congrats to PPP (@PlaidCTF) for collecting more black badges this year and hosting us at the after-party, you guys are awesome! 🚩 #DEFCON27#CTF
Dan Goodin @dangoodin001 has covered our research on aircraft landing systems as one of @arstechnica today's feature stories. https://t.co/uB913oONAl Thank you @ihackedwhat, @dalfry for the comments. Thank you @dangoodin001 for the fantastic report.
ETH doctoral students of #computer science show how linking two popular technologies can have highly problematic consequences for web services such as e-voting systems. https://t.co/mz0gJHBl6H
Wie sich elektronische Abstimmungen kaufen lassen. Die ETH-Studie zu Crowdturfing und E-Voting aus der gestrigen Zeitung https://t.co/NPQTtsdCOO ist mittlerweile erschienen. Hier: https://t.co/fpLHILhEBJ verfasst von @dn0sar et al.
Our entire team at the #riscv summit. From the left - Michael, Florian, Alex The Bear 🐻, Ivan, Moritz, and Matheus.
Look @LucaBeniniZhFe they are all wearing the #PULP t-shirts 👕.
@ms_snowman@be4web @suehtamacv
#IntegriKey: a new way to make sending messages safe, even in a #hostile environment! First product of its kind on the market: #WANTED academics and industrial partners for further development. @SrdjanCapkun https://t.co/FP247bwbR5 https://t.co/U59aBBYQL4
Email triage strategy
- Not important: mute
- Important: answer immediately
- VERY IMPORTANT: wait until I can answer in detail, oh no it's been a month and I still haven't answered, oh god it's been another month, maybe I can change my name and move to Alaska