3 ms·
> 6. Someone points out that in higher level languages it's hard to write code that is resistant against timing attacks. The discussion dies. This doesn't matt
by briansmith 11y ago
> 6. Someone points out that in higher level languages it's hard to write code that is resistant against timing attacks. The discussion dies.
This doesn't matter, because the code that should be resistant to timing attacks should be written in assembly language or a language specially designed for that purpose (that doesn't exist yet) anyway. High-level languages have ways of accessing code written in assembly language.
Anyway, my point is that all these things are solvable.
- heinrich5991 11y agoRust has some compiler plugin magic that can help you write code resistant to timing attacks.
- msbarnett 11y ago> This doesn't matter, because the code that should be resistant to timing attacks should be written in assembly language This would put you right back into buffer overflow territory...
- dbaupp 11y agoIt's unfortunate, but the approach would hopefully be to write the smallest possible primitives in assembly and then use a safer language for the rest of the code that either doesn't need constant time guarantees, or gets those guarantees by building on the primitives. This means that verification against these sort of basic attacks can be focused on a much smaller amount of code, rather than every single location in the whole code-base that manipulates memory (as in C). (And, one can go a step further: extract assembly from some higher-level language/DSL designed to create constant time code.) In any case, the code in question for this post doesn't seem to be written to be timing sensitive.