2 ms·
This Mozilla post https://blog.mozilla.org/security/2018/01/03/mitigations-landing-new-class-timing-attack/ https://blog.mozilla.org/security/2018/01/03/mitigat
by floatboth 9y ago
This Mozilla post https://blog.mozilla.org/security/2018/01/03/mitigations-landing-new-class-timing-attack/ https://blog.mozilla.org/security/2018/01/03/mitigations-lan... mentions that "other timing sources and time-fuzzing techniques are being worked on".
The paper they linked to references this one: https://www.usenix.org/system/files/conference/usenixsecurity16/sec16_paper_kohlbrenner.pdf https://www.usenix.org/system/files/conference/usenixsecurit...
I think this is what all sandboxes have to do: set the TSC disable flag, restrict system timer precision (make it configurable per sandbox: web servers generally don't need more than 1ms precision), make system timer report fuzzy (randomized) time. Heck, why not also make the CPU run at randomized frequency to mess with busy loop timers.