3 ms·
Given how long side channels and timing attacks have been causing problems why haven't compilers tried to meet the requirements of crypto authors and implemento
by ShorsHammer 6y ago
Given how long side channels and timing attacks have been causing problems why haven't compilers tried to meet the requirements of crypto authors and implementors?
Feels like people are fighting against compiler optimisations more than ever.
- ganafagol 6y agoCrypto code and non-crypto code have different requirements. For compiling non-crypto code you often want the fastest code that still matches the language spec. "Fast" is usually even relative to target platform. For crypto code, you need a very narrowly defined abstract machine that you program against and since that's a much stronger requirement than what the language is defined for, you take the next best thing by turning off all optimizations and hoping you understand well enough how your compiler generates code. In other words, they already do their best by giving authors control over how much optimization is applied. Anything beyond that is a language design problem, not compiler construction problem.