3 ms·
I don't think this is correct. The timing attacks here all require extremely high resolution timers, and network + I/O latency would obscure the variance entire
by bannable 7y ago
I don't think this is correct. The timing attacks here all require extremely high resolution timers, and network + I/O latency would obscure the variance entirely.
- dymk 7y agoPeople are able to crack poor password comparison implementations over a jittery, latency heavy network. It’s possible to get almost arbitrarily high resolution when doing timing side channel attacks, you’ll just need many more samples.