@BRIAN_____ It thus seems wrong that program verification tools tend to take high-level (e.g. C) code as input instead of compiled binaries.
@h4nnes Why can't we prove absence of side channels? Because we can't prove hardware side-channel-free? Can't we can prove a lot regardless?
-
-
@BRIAN_____ because side channels are very CPU specific (timing of operations can depend on arguments)... beware of smartness of compilers.. -
@BRIAN_____ luckily there's research http://arxiv.org/abs/1506.00189 http://askarov.net/pltiming-pldi12.pdf … and likely other...
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.