RSSAmplifier

Blog

Lukas Gerlach

Lukas Gerlach

lukasgerlach.meRSS feed ↗28 posts

Latest posts

Spectre on RISC-V Silicon: Attacks and Defenses on Commercial Out-of-Order Processors

Spectre on RISC-V Silicon

Our paper Spectre on RISC-V Silicon: Attacks and Defenses on Commercial Out-of-Order Processors has been accepted at USENIX Security ‘26 . Paper / Artifact This post is the short version of what we found. RISC-V is an open, modular instruction set architecture that anyone can implement without a license fee. Many independent vendors build their own cores from it, ranging from tiny in-order…

How do Cache Attacks Against AES Work?

AES is the most widely used block cipher, and there are some cache side-channel attacks against it. The attacks always exploit key-dependent memory accesses because parts of AES are optimized with lookup tables. This post quickly goes over the lookup table optimizations called S-boxes and T-tables, and how such implementations can be attacked. My hope is that this can help quickly understand the…

Crucible: Retrofitting Commodity CPUs with Vulnerabilities via Transparent Software Emulation

TDXRay: Microarchitectural Side-Channel Analysis of Intel TDX for Real-World Workloads

Zero-Store Elimination and its Implications on the SIKE Cryptosystem

RISCover: Automatic Discovery of User-exploitable Architectural Security Vulnerabilities in Closed-Source RISC-V CPUs

Confusing Value with Enumeration: Studying the Use of CVEs in Academia

SCASE: Automated Secret Recovery via Side-Channel-Assisted Symbolic Execution

Taming the Linux Memory Allocator for Rapid Prototyping

Rapid Reversing of Non-Linear CPU Cache Slice Functions: Unlocking Physical Address Leakage

Do Compilers Break Constant-time Guarantees?

Lixom: Protecting Encryption Keys with Execute-Only Memory

Cascading Spy Sheets: Exploiting the Complexity of Modern CSS for Email and Browser Fingerprinting

ShadowLoad: Injecting State into Hardware Prefetchers

Peripheral Instinct: How External Devices Breach Browser Sandboxes

No Leakage Without State Change: Repurposing Configurable CPU Exceptions to Prevent Microarchitectural Attacks

CacheWarp: Software-based Fault Injection using Selective State Reset

Efficient and Generic Microarchitectural Hash-Function Recovery

A Security RISC? The State of Microarchitectural Attacks on RISC-V

Rowhammer Revisited: From Exploration to Exploitation and Mitigation

A Rowhammer Reproduction Study Using the Blacksmith Fuzzer

Indirect Meltdown: Building Novel Side-Channel Attacks from Transient-Execution Attacks

Reviving Meltdown 3a

Collide+Power: Leaking Inaccessible Data with Software-based Power Side Channels

Hammulator: Simulate Now-Exploit Later

A Security RISC: Microarchitectural Attacks on Hardware RISC-V CPUs

CSAW Applied Research Competition Finalist