Hacker News new | ask | show | jobs
by jacquesm 3084 days ago
I would not at all be surprised if Spectre and Meltdown were already known at nation state level, they have a lot of resources to throw at problems like this. The fact that Google provides this service for free is an amazing counterbalance to that kind of power, the bugs don't magically disappear but at least the playing field has been leveled a bit.
1 comments

It is my impression that analysis of side channels has been done and professionalized in the intelligence community for a long time before it became an important consideration in the general IT community.
Adi Shamir, the S in RSA, has done tons of work on side channel analysis, especially of hardware crypto, for decades. Timing attacks, voltage attacks, EM, you name it.

So it's not unknown. But as a counterpoint I had a shocking moment in the 90's when I learned that Faraday Cages (to prevent TEMPEST attacks) were being designed with a second Faraday cage inside them to protect the light bulbs.

Seems that the interference between a CRT and a fluorescent bulb are sufficient that you can detect information on the power lines leading into the room. So they caged the bulbs to keep them magnetically isolated from the computers.