Tag: Side-Channel Attack

Microsoft Uncovers ‘Whisper Leak’ Attack That Identifies AI Chat Topics in Encrypted Traffic
News

Microsoft Uncovers ‘Whisper Leak’ Attack That Identifies AI Chat Topics in Encrypted Traffic

Microsoft has revealed specifics about a new side-channel attack aimed at remote language models. This attack could allow a passive adversary with the ability to monitor network traffic to extract information about conversation topics within the model, even when encryption is in place, under certain conditions. The company indicated that this leakage of data shared between individuals and streaming-mode language models could significantly threaten the privacy of user and enterprise communications. The assault has received the codename Whisper Leak. Cyber attackers who can monitor encrypted traffic (such as a nation-state actor at the internet service provider layer, an individual on the local network, or someone using the same Wi-Fi connection) may leverage this cyber attack to dedu...
New TEE.Fail Side-Channel Attack Extracts Secrets from Intel and AMD DDR5 Secure Enclaves
News

New TEE.Fail Side-Channel Attack Extracts Secrets from Intel and AMD DDR5 Secure Enclaves

Researchers from Purdue University, Georgia Tech, and Synkhronix have created a side-channel attack known as TEE.These include AMD's Secure Encrypted Virtualization with Secure Nested Paging (SEV-SNP) and Ciphertext Hiding, and Intel's Software Guard eXtensions (SGX) and Trust Domain Extensions (TDX), which enable the extraction of secrets from the trusted execution environment (TEE) in a computer's main processor. Fundamentally, the attack uses an interposition device that allows for the physical inspection of all memory transactions within a DDR5 server. It is constructed using readily available electronic equipment and costs less than $1,000. According to an informational website, this enables us to extract cryptographic keys from AMD SEV-SNP and Intel TDX for the first time usin...