Products
Features
YouTube Video Summarizer
Summarize YouTube videos
Web & PDF Highlighter
Highlight web pages & PDFs
Chat with PDF
Ask any PDF questions with AI
Ask AI Clone
Chat with your highlights & memories
Audio Transcriber
Transcribe audio files to text
Glasp Reader
Read and highlight articles
Kindle Highlight Export
Export your Kindle highlights
Idea Hatch
Hatch ideas from your highlights
Integrations
Obsidian Plugin
Notion Integration
Pocket Integration
Instapaper Integration
Medium Integration
Readwise Integration
Snipd Integration
Hypothesis Integration
Apps & Extensions
Chrome Extension
Safari Extension
Edge Add-ons
Firefox Add-ons
iOS App
Android App
Discover
Discover
Ideas
Discover new ideas and insights
Articles
Curated articles and insights
Books
Book recommendations by great minds
Posts
Essays and notes from readers
Quotes
Inspiring quotes collection
Videos
Curated videos and summaries
Explore Glasp
Glasp Newsletter
Weekly insights and updates
Glasp Talk
Interview series with great minds
Glasp Blog
Latest news and articles
Glasp Use Cases
Learn how others use Glasp
Build & Support
Glasp API
Access Glasp's API for developers
MCP Connector
Connect Glasp to Claude & ChatGPT
Community
Glasp Reddit Community
Students
Student discount and benefits
FAQs
Frequently Asked Questions
AboutPricing
DashboardLog inSign up

What's Behind Port Smash? - Computerphile

November 13, 2018
by
Computerphile
YouTube video player
What's Behind Port Smash? - Computerphile

TL;DR

Port Smash, also known as port contention for fun and profit, exploits hyper-threading to extract private keys from OpenSSL programs running on Intel CPUs.

Transcript

There's been some noise over the past week about and a paper that's come out and an exploit the papers called port contention for fun and profit people be referring it Port Smash. So what it does is it actually you got open ssl running and it's using a private key and you've got another program which they call that spy program which runs alongside ... Read More

Key Insights

  • 🎨 Port Smash exploits hyper-threading, a feature designed to improve CPU performance and efficiency.
  • 🤩 By monitoring and analyzing timings of instructions, Port Smash can infer the operations being executed by a program and extract sensitive information like private keys.
  • 🪡 This exploit highlights the potential risks associated with hyper-threading and the need to consider disabling or modifying it for certain applications.
  • 👤 It is important for CPU manufacturers to address vulnerabilities like Port Smash to protect user data and ensure the security of cryptographic processes.
  • 💝 System administrators and users should stay informed about the latest security updates and patches to mitigate the risk of such exploits.
  • 🛟 Port Smash serves as a reminder that even seemingly unrelated features, like hyper-threading, can have unintended security implications.
  • 🔒 Researchers and security professionals play a critical role in discovering and addressing vulnerabilities like Port Smash to enhance overall system security.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What is hyper-threading and how does it improve CPU performance?

Hyper-threading allows a single physical core to appear as two logical cores, enabling simultaneous execution of two instruction streams and better utilization of CPU resources.

Q: How does Port Smash exploit hyper-threading?

Port Smash runs alongside an OpenSSL program and measures the timings of certain instructions. By analyzing the timings, the exploit can infer the instructions being executed and extract the private key used by OpenSSL.

Q: Is Port Smash limited to a specific operating system?

Port Smash is not operating system specific but rather CPU specific. It was demonstrated on Intel Skylake and Kaby Lake CPU families but could potentially be adapted to other CPUs with hyper-threading.

Q: Can hackers easily exploit this vulnerability?

While the example code for Port Smash is available on GitHub and can be run on Linux machines, successfully exploiting this vulnerability may depend on specific system configurations. However, with the right circumstances, it is feasible for hackers to extract sensitive information using this exploit.

Summary & Key Takeaways

  • Port Smash is a recently discovered exploit that targets hyper-threading in Intel and AMD CPUs.

  • Hyper-threading allows a single physical core to appear as two logical cores, improving efficiency.

  • The exploit uses a spy program to monitor the timings of certain instructions and extract private keys from OpenSSL programs.


Read in Other Languages (beta)

English

Share This Summary 📚

Summarize YouTube Videos and Get Video Transcripts with 1-Click

Download browser extensions on:

Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator

Explore More Summaries from Computerphile 📚

Breaking RSA - Computerphile thumbnail
Breaking RSA - Computerphile
Computerphile
Stable Diffusion in Code (AI Image Generation) - Computerphile thumbnail
Stable Diffusion in Code (AI Image Generation) - Computerphile
Computerphile
Triple Ref Pointers - Computerphile thumbnail
Triple Ref Pointers - Computerphile
Computerphile
Error Detection and Flipping the Bits - Computerphile thumbnail
Error Detection and Flipping the Bits - Computerphile
Computerphile
Mainframes and the Unix Revolution - Computerphile thumbnail
Mainframes and the Unix Revolution - Computerphile
Computerphile
The Problem with Time & Timezones - Computerphile thumbnail
The Problem with Time & Timezones - Computerphile
Computerphile

Summarize YouTube Videos and Get Video Transcripts with 1-Click

Download browser extensions on:

Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator

Apps & Extensions

  • Chrome Extension
  • Safari Extension
  • Edge Add-ons
  • Firefox Add-ons
  • iOS App
  • Android App

Key Features

  • YouTube Video Summarizer
  • Web & PDF Summarizer
  • Web & PDF Highlighter
  • Chat with PDF
  • Ask AI Clone
  • Audio Transcriber
  • Glasp Reader
  • Kindle Highlight Export
  • Idea Hatch

Integrations

  • Obsidian Plugin
  • Notion Integration
  • Pocket Integration
  • Instapaper Integration
  • Medium Integration
  • Readwise Integration
  • Snipd Integration
  • Hypothesis Integration

More Features

  • APIs
  • MCP Connector
  • Blog & Post
  • Embed Links
  • Image Highlight
  • Personality Test
  • Quote Shots

Company

  • About us
  • Blog
  • Community
  • FAQs
  • Job Board
  • Newsletter
  • Pricing
Terms

•

Privacy

•

Guidelines

© 2026 Glasp Inc. All rights reserved.