Light

Episode #967 Quiz

GoFetch
Date: 2024-03-26 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

GoFetch exploits Apple and Intel data memory-dependent prefetchers: cacheable pointer-like data triggers speculative dereferencing, creating a cache side channel that leaks cryptographic secrets even from constant-time implementations. The attack can extract RSA, Diffie-Hellman, Kyber, and Dilithium keys locally. Mitigations include disabling DMP on M3 and moving crypto to safer cores.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode, what did Apple add to M3 chips that makes the GoFetch issue avoidable on that generation?
Question 2: What was the key technique the researchers used to turn DMP into a key-extraction side channel?
Question 3: Which of the following accurately summarizes the affected Apple chip generations as Steve described them?
Question 4: Why did Steve say the headline claims about GoFetch were overstated?
Question 5: What did Steve identify as the likely practical impact if the attack were used in the real world?
Cancel