<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Workers on dbalog.dev</title>
    <link>https://dbalog.dev/tags/workers/</link>
    <description>Recent content in Workers on dbalog.dev</description>
    <generator>Hugo</generator>
    <language>ko</language>
    <lastBuildDate>Mon, 24 Aug 2026 12:00:00 +0900</lastBuildDate>
    <atom:link href="https://dbalog.dev/tags/workers/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>초당 12비트로 새어 나온 JWT: Cloudflare Workers에서 다시 열린 Spectre</title>
      <link>https://dbalog.dev/posts/cloudflare-workers-spectre-revisit/</link>
      <pubDate>Mon, 24 Aug 2026 12:00:00 +0900</pubDate>
      <guid>https://dbalog.dev/posts/cloudflare-workers-spectre-revisit/</guid>
      <description>Cloudflare가 자사 Workers 프로덕션 환경에서 원격 Spectre 공격을 재현한 연구를 공개했습니다. WebSocket으로 받은 타임스탬프만으로 초당 12비트, 정확도 99% 이상으로 다른 테넌트의 JWT를 읽어 냈습니다. 프로세스 대신 V8 isolate로 수만 테넌트를 나누는 구조가 어떤 대가를 치르는지, 2021년 방어가 왜 이 공격을 놓쳤는지, 그리고 새로 붙인 V8 샌드박스와 MPK가 무엇을 막는지 정리합니다.</description>
    </item>
  </channel>
</rss>
