[Cryptography] Spectre -- would an L0 for speculation-only help?

Jon Callas jon at callas.org
Thu Jan 11 20:13:02 EST 2018



> On Jan 11, 2018, at 11:20 AM, Nico Williams <nico at cryptonector.com> wrote:
> 
> Is this crazy?

No.

>  Workable?  

Probably not.

> If so, would there still be timing side-
> channel attacks on speculative execution left unadressed?

Yes, there would, so long as you have a coherent cache, and without one, you blow speculation or have to introduce a whole new mechanism to restart if there's an incoherent cache, which is both hard and probably leaks.

>  Perhaps there
> might be timing leaks via cache coherency effects?

Yup, that's basically the conundrum.

	Jon



More information about the cryptography mailing list