5 ms·
100ms is /massive/ for a timing delta but you really need a lot of samples. I have exploited timing deltas that were not much more than a handful of machine cod
by bitexploder 6y ago
100ms is /massive/ for a timing delta but you really need a lot of samples. I have exploited timing deltas that were not much more than a handful of machine code instructions in terms of execution time. But you really do need a lot of samples to confirm small deltas. It starts getting impractical for many APIs (someone will notice, hopefully).
- texasbigdata 6y agoThis comment is why I love hackernews
- bitexploder 6y agoSee: https://rdist.root.org/2010/07/19/exploiting-remote-timing-attacks/ https://rdist.root.org/2010/07/19/exploiting-remote-timing-a... and Crosby 2007. I got into infosec around 06 and tptacek, Nate Lawson and some others were my heroes. Now I run my own consulting firm with a bunch of cool people :) Also in infosec: what is old is new. We still find shitty comparison routines (timing attacks) and SQL injection... some day :)
- dmix 6y ago> someone will notice, hopefully Or more likely "someone will notice, eventually"
- animex 6y agoI just found a use-case for the sleep( rand(1000) ) function :-)
- faeyanpiraat 6y agoNope! If the rand function produces uniform random numbers, then with enough samples the signal comes out ontop the noise. If it is non-uniform, then with enough samples you can determine the non uniformity, and you are at square 1 again. Use proper security instead of obscurity.
- animex 6y agoEasily accommodated for. I can get the execution run-time and store in an average in memory for some time-period and have the sleep function top-up the difference between the two paths. Not sure what the "proper security" method is to prevent execution deltas.
- renewiltord 6y agoWhy not just run the thing (which takes some small fraction of time), then pad to five seconds, and respond. Since your work will be done in milliseconds, padding to nearest five seconds will remove any noise. And it's not a thing anyone has a legitimate interest in submitting more than that per second.
- odonnellryan 6y agoAdding five seconds to everything just adds five seconds, it doesn't matter if the difference between the two requests is .01s or 5.01s.
- throwaway894345 6y agoThe parent said "pad to 5 seconds" not "add 5 seconds". Thus everything would be 5 seconds (never 5.01). The difference between a hit and a miss would be exactly 0s. Note that I'm not advocating for or against this solution; rather, clarifying the conversation.
- renewiltord 6y agoPad to, not pad by. I.e. the padding to add is (5 - duration_of_operation) with duration of operation being far lower than 5 s.
- bitexploder 6y agoDepends. With comparison functions you can implement a constant time comparison that takes the same amount of time. In this case it isn’t really a crypto problem, so anything where we are confident about things taking the same amount of time is fine. Basically in some parent method/func make sure we always spend 2000ms or whatever time is that is always greater than the max runtime of the slowest path. Secondary / defense in depth mitigations would be rate limiting this page and making it purposefully slow on response, just to make it that much harder to collect samples / abuse it without being noticed. The captcha is a nice touch, but it didn’t seem particularly strong (a good captcha solver could break it). Still, captcha will chase off a lot of script kiddies. You don’t have to be faster than the bear, just faster than the slowest person ;)
- wodenokoto 6y agoI would have gone for `sleep(1000)` and have it run in parallel with the actual function, so that every request takes 1000 milliseconds