Multiple side channel attacks expose sensitive data
CPU Vulnerabilities Allow Programs To Access Data Unfettered
Based on latest reports, there have been four waves of Spectre-class vulnerabilities discovered that allow malicious programs to read sensitive data via side channel attacks. This brings the total count to over 30 vulnerabilities discovered this year alone, and raises questions about new threat models that need to be considered in the security architecture.
These new hardware-based vulnerabilities will create multiple challenges in that they take longer to fix and patch, and as companies move to cloud providers, there are no guarantees for what hardware the applications are running on. Put another way, the computing ground people thought they were all standing on to process data, doesn’t seem as stable given these new security gaps.
Baffle delivers a transparent data protection service layer that secures data at the field or file level via a "no code" model. The solution supports tokenization, format preserving encryption (FPE), database and file AES-256 encryption, privacy preserving analytics and access control. As a transparent solution, cloud native services are easily supported with almost no performance impact.
No application code modification
Virtually no performance
Integrates easily into your
AES encryption in memory, in use,