4 ms·
if you arent running vms, you can chill.
by modzu 5y ago
if you arent running vms, you can chill.
- 4ad 5y agoNo you can't, attacks like spectre are exploitable from javascript.
- Filligree 5y agoHas anyone seen an attack in the wild, though? Ever?
- crazysim 5y agoPeople were doing POCs before the browser makers nerfed the hell out of timing APIs especially from web assembly and autoupdate distributed the nerfs out.
- davidw 5y agoWhat does 'nerfed' mean in this context?
- mekkkkkk 5y ago'Nerf' is a term used for when game developers update a game and reduce the effectiveness of something. 'My sword attack ability was nerfed in the latest patch'. In this context I suppose the API capabilities was reduced in browser updates.
- mook 5y agoIn particular, the word is derived from a brand of toy foam arrows. Basically, it refers to negating the possible damage of something.
- Iv 5y agoLower the precision by adding random noise.
- cmg 5y agoBrowser manufacturers changed the behavior of APIs like performance.now() [0] to add slight rounding 'errors' or limit the granularity of timing functions. That function used to report on the microsecond level in (most) browsers, but now is generally limited to around 1ms due to timing attacks. [0] https://developer.mozilla.org/en-US/docs/Web/API/Performance/now https://developer.mozilla.org/en-US/docs/Web/API/Performance...
- a-dub 5y agosurely high precision clocks can be constructed via busy waits or random api calls that hit hardware to do things with fixed latency, no?
- silon42 5y agoAll those can be limited, because thankfully JS is not multithreaded (otherwise you could do busy-loop timing).
- staticassertion 5y agoYes, like the SharedArrayBuffer that browsers disabled. There are probably roughly infinite ways to construct clocks. Closing the obvious leaks has been a stop gap while other mitigation techniques are rolling out, like site isolation.