Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

SNeela

@vmcall@infosec.exchange
  • Open on infosec.exchange

PhD student working on system security, side-channel security, and CPU security at @isec_tugraz@infosec.exchange, TU Graz, Austria.

Hardware equivalent of a Sticky Note :debian:

Probably will talk about #linux, #security, #systems, and #filmphotography. Oh, and also chonk the #plushtodon

Opinions posted here are my own.

0 Followers
0 Following
4 Posts
Joined July 04, 2023
website:
https://snee.la
film photography:
https://fotos.snee.la/

Posts

Open post
vmcall
SNeela @vmcall@infosec.exchange · Jul 27, 2026
SNeela
@vmcall@infosec.exchange

PhD student working on system security, side-channel security, and CPU security at @isec_tugraz, TU Graz, Austria. Hardware equivalent of a Sticky Note :debian: Probably will talk about #linux, #security, #systems, and #filmphotography. Oh, and also chonk the #plushtodon Opinions posted here are my own.

infosec.exchange
I'm happy to announce our work has been accepted at ESORICS 2026, going to be held at Rome, Italy in September later this year! "A Systematic Look at Quality-of-Service Feature Effects on Side Channels in AMD SEV-SNP" In our work, we show that AMD CPUs' Quality of Service features introduce and amplify side channels, especially concerning in the confidential computing / trusted execution paradigm of computing. We show that a malicious hypervisor can use allocation and monitoring features to leak and amplify what's going on in an AMD SEV-SNP confidential VM. The hypervisor can mount keystroke detection attacks, website fingerprinting attacks, Bleichenbacher attacks on RSA, and covert channels. We reported our findings to AMD, who said that "side channels are not in their threat model for SEV-SNP"... 🙂. I have a blog write up here (there's a logo of a cat wearing a business tie - no AI): https://snee.la/posts/amd-qos-side-channels/ You can read the paper at: https://snee.la/pdf/pubs/amd-qos-side-channels.pdf Thanks to Carina Fiedler, @Rayiizzz@infosec.exchange, @supersingular@chaos.social, @misc0110@infosec.exchange and @lavados@infosec.exchange for the fun collaboration! :1000: #esorics2026 #confidentialcomputing #amd #security #cloud #computing #cloudcomputing
9
0
9
0
Open post
vmcall
SNeela @vmcall@infosec.exchange · Jul 20, 2026
SNeela
@vmcall@infosec.exchange

PhD student working on system security, side-channel security, and CPU security at @isec_tugraz, TU Graz, Austria. Hardware equivalent of a Sticky Note :debian: Probably will talk about #linux, #security, #systems, and #filmphotography. Oh, and also chonk the #plushtodon Opinions posted here are my own.

infosec.exchange
Yesterday evening, the moon had this wonderful red-orange color to it. Using my brand new Tamron 300mm lens, I took this beautiful shot with my Sony Alpha 6500. ISO 100 Exposure Time: 6/10 of a second
0
0
0
0
Open post
vmcall
SNeela @vmcall@infosec.exchange · Jul 02, 2026
SNeela
@vmcall@infosec.exchange

PhD student working on system security, side-channel security, and CPU security at @isec_tugraz, TU Graz, Austria. Hardware equivalent of a Sticky Note :debian: Probably will talk about #linux, #security, #systems, and #filmphotography. Oh, and also chonk the #plushtodon Opinions posted here are my own.

infosec.exchange
Keep Android Open: https://keepandroidopen.org #KeepAndroidOpen
0
0
0
0
Open post
vmcall
SNeela @vmcall@infosec.exchange · May 09, 2026
SNeela
@vmcall@infosec.exchange

PhD student working on system security, side-channel security, and CPU security at @isec_tugraz, TU Graz, Austria. Hardware equivalent of a Sticky Note :debian: Probably will talk about #linux, #security, #systems, and #filmphotography. Oh, and also chonk the #plushtodon Opinions posted here are my own.

infosec.exchange

Davide Ornaghi and Giuseppe Caruso found a very interesting bug in #Linux's in-kernel Samba3 server from 6.12 to 6.19.x. Essentially, from the commit message and #CVE description:

> Currently, ksmbd does not verify if the user attempting to reconnect to a durable handle is the same user who originally opened the file. This allows any authenticated user to hijack an orphaned durable handle by predicting or brute-forcing the persistent ID.

Very interesting stuff! The kernel let's users resume their connection to an open file even after WiFi drops (durable handle), and a bug in this code let another authenticated user become this WiFi-dropped user, letting the hijacker access all files.

https://github.com/TurtleARM/CVE-2026-31717-KSMBD-Exploit

CVE-2026-31717

infosec.exchange

Infosec Exchange

3
0
2
0

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 18:14:45 UTC