Associate Professor at Georgia Tech. Security, systems, side channels, cryptography.

Atlanta, GA
1/2 After two weeks of TEE.fail being public (and additional 6+ month of private disclosure) Intel has finally revoked one of several CPUs used for @Teedotfail. This means that the Xeon chip below has made the ultimate sacrifice and will never run SGX or TDX again.
3
15
176
29,818
2/2 Its legacy however lives on, being the first demonstration of an end-to-end TDX break. Other CPUs have already risen to take its role, with the server being operational by simply plopping a fresh CPU from the tray. This one however is going to a cherished place on the shelf.
2
34
4,616
Daniel Genkin retweeted
Replying to @DanielGenkin
Your message "More interposer fun, this time with DDR5 memory. Breaking TDX, S..." has been signed. Check out your quote at: view.tee.fail/view/45ecffd7c… and visit tee.fail for more info.
40
6
51
30,866
More interposer fun, this time with DDR5 memory. Breaking TDX, SGX, SEV and even Nvidia TEEs. Checkout our work at TEE.fail, and get a personally-signed Intel attestation report at @TEEdotFail.
42
83
343
138,017
Want to know what happens when commercial TEEs meet improvised DRAM memory interposers? SGX mayhem including attestation key extraction. Please DO try that at home😉. Check out our work at wiretap.fail/
7
61
207
59,114
Have an Apple device from the last few years? We have a new side channel attack for you. Checkout our work at predictors.fail/ Joint work with Jason Kim, Jalen Chuang and Yuval Yarom (@yuvalyarom). Could not have asked for a better team!
1
28
78
9,797
Daniel Genkin retweeted
Our work on page walk side channels was accepted at @IEEESP 2025 (#ieeesp2025)! The full paper is now available at: gofetch.fail/files/peek-a-wa… and our code is available at: github.com/FPSG-UIUC/Peek-a-…
1
8
25
4,008
Daniel Genkin retweeted
Excited to present "Pathfinder: High-Resolution Control-Flow Attacks Exploiting the Conditional Branch Predictor" at @ASPLOSConf with Archit Agarwal, Max Christman, @CryptoGPS, @DanielGenkin, Andrew Kwong, @flowyroll, @deiandelmars, @mktaram and Dean Tullsen. (1/4)🧵
2
11
50
15,710
GoFetch.fail happening now @RealWorldCrypto. Come see Boru Chen (@blue75525366) talking about breaking constant time crypto using fancy prefetchers on Apple CPUs
5
20
3,981
Ever wondered what happens when side-channel resistant code meets a fancy prefetcher? Checkout our paper breaking constant time crypto on Apple CPUs. gofetch.fail/ Joint work with Boru Chen, @YingchenWang96, @PradyumnaShome, Chris Fletcher, @dkohlbre, @ricpacca
1
30
86
9,388
I'm very thankful to the @SloanFoundation for recognizing my research. Could not have done it without my awesome students, great collaborators, and wonderful mentors. Checkout our research group that made this possible at architecture.fail/
We have today announced the names of the 2024 Sloan Research Fellows! Congratulations to these 126 outstanding early-career researchers: sloan.org/fellowships/2024-F…
4
3
27
4,098
Microarchitectural unboxing: check out our new demo for breaking two factor authentication using iLeakage. Yes you heard it, speculative execution attacks on Apple’s M3 Macs and latest Safari that defeat Facebook’s 2FA over SMS. ileakage.com/
14
36
7,228
Daniel Genkin retweeted
Goodbye WOOT the Workshop, hello WOOT the Conference! Excited to be a part of this legacy and this new beginning.
WOOT! Big news! Starting 2024 WOOT will be @USENIX WOOT Conference on Offensive Technologies! WOOT '24 will be on August 12-13 2024, colocated with USENIX Security WOOT '24 will be co-chaired by @noopwafel (@intel) and @adamdoupe (@uarizona) usenix.org/conference/woot24
1
8
74
6,842
WOOT! Big news! Starting 2024 WOOT will be @USENIX WOOT Conference on Offensive Technologies! WOOT '24 will be on August 12-13 2024, colocated with USENIX Security WOOT '24 will be co-chaired by @noopwafel (@intel) and @adamdoupe (@ASU <= corrected!) usenix.org/conference/woot24
1
17
50
11,631
For those wondering if Apple’s iOS/iPadOS 17.1 and macOS 14.1 released yesterday protect against ileakage.com/? We took a look for you, the answer is no. Devices are still vulnerable.
1
18
26
9,541
Daniel Genkin retweeted
iLeakage: Speculative execution attack on Safari, iPhone, iPad and Mac, allowing a hostile website to extract your passwords and other secrets. ileakage.com/ The only way to be safe is to stop using Safari: At the time of public release, Apple has implemented a mitigation for iLeakage in Safari. However, this mitigation is not enabled by default, and enabling it is possible only on macOS. Furthermore, it is marked as unstable.
10
85
160
99,945
After more than a year of embargo we can now show you how speculative attacks can extract sensitive information from the Safari browser on @Apple platforms. Check out our latest paper ileakage.com/. Great work by Jason Kim, @themadstephan and @yuvalyarom.
3
51
133
20,583