3 ms·
The attack isn't nicely asking the computer "hey how fast are you running right now?" and then deriving the private key from that data. If that was the case the
by Phlarp 4y ago
The attack isn't nicely asking the computer "hey how fast are you running right now?" and then deriving the private key from that data. If that was the case the fix would be as simple as you laid out here.
This attack works by measuring the absolute (wall) time that elapses during many crypto operations and deriving the speed / private keys based on statistical methods applied to that timing data.
Side-channel attacks are by definition, attacks against unintentional information leakage by a machine. The laws of thermodynamics virtually ensure that side channel attacks will be a persistent issue as long as computers are made of matter and consume electricity, multi-tenant computing exacerbates the issue.
- tester756 4y agothank you