[OC] Behold, a *flappy* duck
[OC] Behold, a *flappy* duck
Thanks for the question!
As long as caches have existed, very similar styles of side channels have been demonstrated since the late 90s. A lot of the terminology we use (flush+reload, flush+flush…) are attack techniques that have been already demonstrated on CPU caches, and these demonstrations are at least a decade old.
Flush+Reload: www.usenix.org/conference/…/yarom
Flush+Flush: gruss.cc/files/flushflush.pdf
Invalidate+Compare (GPU caches, 2024): www.usenix.org/conference/…/zhang-zhenkai
My colleague, Hannes, found similar styles of attacks existed with the Linux DNS cache too: hannesweissteiner.com/pdfs/dmt.pdf (also published at NDSS 26!)
The one really big difference between the page-cache side channel and other side channels is the “monitor” primitive. There are methods that the OS provides which directly report the presence of a page in cache. These are syscalls like mincore (mitigated in 2019), preadv2 + rwf_nowait (unmitigated), and cachestat (mitigated in 2025).
With these syscalls, we don’t even have to rely on timing information (is page access fast -> cached; is it slow -> not cached). These syscalls really set the page-cache side channel apart because you can nondestructively figure out whether a page is in cache.
The page-cache side channel was first explored in 2019. It was explored on Linux but also on Windows by my advisor et al.: gruss.cc/files/pagecacheattacks.pdf
Hope this answers your question :D
CCC just wrapped up two days ago. events.ccc.de/congress/2025/infos/startpage.html
This happens every year with CCC, Defcon, and Blackhat. There are always interesting talks and you get a slew of posts from interested people.
Thank you for the comment!
Most of the beautiful hardwork was done by the store - I just pointed, zoomed, focused, and shot. It doesn’t feel like I did much to the already existing grandeur.
A Collection of Christmas ornaments [OC]
I haven’t seen anyone here mention Psyllium husk. I bought 450 capsules on Amazon (ew I know) and it’s been a game changer for me. Seriously.