3 ms·
The author's conclusion to question of "are timing attacks viable?" seems to be... it depends on the nature of the language or library. Are most devs going to u
by jamilbk 2y ago
The author's conclusion to question of "are timing attacks viable?" seems to be... it depends on the nature of the language or library. Are most devs going to understand these nuances though?
In the time it takes to research the timing behavior of your runtime, you could have reached for a constant-time comparison instead.
Similarly, in the time it takes you to reach the conclusion the comparison you're using isn't vulnerable, you could have reached for a secure compare instead.
I'm not convinced this post makes a compelling case against the best practice of always using a secure compare for secret strings.
- teo_zero 2y agoIn fact the bottom line is > The time differences for individual characters are often below one nanosecond, making it virtually impossible to detect remotely. What I'm taking away is: scrutinizing the algorithm used for string comparison should be low priority compared to other security-related concerns.