2026-10-11 17:13 UTC

Independent reproduction and Cloudflare's mitigations will determine whether remote timers enable practical Spectre-style cross-tenant leakage in Cloudflare Workers.

state: seedheat: lowuncertainty: highconvergesscott: highcloud-security side-channel-attacks infrastructure-isolation agentic-securityCloudflare

What is this?

A reported paper claims a remote Spectre-style attack against a co-located Cloudflare Workers victim, allegedly leaking a JWT at up to 12 bits per second, though the supplied snippets do not independently substantiate the paper’s method or results. Cloudflare’s published security model suppresses local timers and multithreading and uses dynamic process isolation, while acknowledging that remote time servers, amplification, repetition, and statistical analysis could theoretically recover timing signals. Cloudflare says its own adversarial testing has not produced a remote timing attack that works in production, so the practical exploitability and effectiveness of current mitigations remain disputed in the supplied material.

Why it matters to Scott

If independently reproduced, the claimed cross-tenant leak would materially support Scott’s existing position that untrusted execution needs defense-in-depth and preferably single-tenant, credential-separated containment rather than reliance on a shared-runtime sandbox boundary. It bears directly on the active SiloOS architecture and creates a dated-receipts opportunity, although Cloudflare’s dispute means the evidence remains conditional.
ip:concept.sandboxed-executionip:framework.siloosip:concept.defense-in-depthdev:project.silo-osdev:concept.single-tenant-ai-applianceradar:concept.side-channel-attacksradar:concept.sandboxingradar:sparsety-sparse-serving-token-leak
queries asked of Scott's wikis
  • untrusted code sandboxing and cross-tenant isolation
  • remote timing side channels in shared runtimes
  • agent execution security and secret isolation
  • process isolation versus isolate-based multitenancy
  • security boundaries for edge and serverless compute
  • independent reproduction standards for security claims

Measured heat

now 0 pts/hpeak 0 pts/hcomments 0/hpeers p14momentum: steady2 platformsage 1346h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion

How the heat travelled

08-16 14:00⭐ origin echo-reconstructedThe paper reports a remote Spectre attack against a co-located Cloudflare Workers victim, leaking a JWT at up to 12 bits/second, and describ
Martin Schwarzl, Haocheng Xiao, Albert Pedersen, Sam Ainsworth, Nigel Topham on paper (echo) · attributed from hn.story.49364721
—
08-19 17:45first on hacker news · published · +75.8hA revisit of remote Spectre attacks on Cloudflare Workers
albertpedersen
—
08-19 17:45amplified on hacker news 👑hn.story.49364721
albertpedersen
peak 76 · 4 comments · 100% of case engagement
08-19 20:21our radar first saw it · +78.4hdiscovery anchor: hn.story.49364721—

Evidence (2) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnA revisit of remote Spectre attacks on Cloudflare Workersalbertpedersen764
🟧 echo.paper ⭐The paper reports a remote Spectre attack against a co-located Cloudflare Workers victim, leaking a JWT at up to 12 bits/second, and describMartin Schwarzl, Haocheng Xiao, Albert Pedersen, Sam Ainsworth, Nigel Topham——

Interpretation history

Decision trace