3 ms·
Well, you could have these "sleeper weights" only act on a specific day, rather than "$day + N", then people would have to prod every single future date to see
by embedding-shape 2mo ago
Well, you could have these "sleeper weights" only act on a specific day, rather than "$day + N", then people would have to prod every single future date to see if it could be malicious on that specific day, seems like a hassle. But I guess would be the only way really to detect it?
- eru 2mo agoIf it's only the day (and not time of day), then securing the next ten years would only take around ~3650 trials. Doesn't seem too bad. (And the can't make it too precise, if they want their attack to work even if you don't use the tool at exactly the right microsecond.)
- embedding-shape 2mo agoYeah, at a glance doesn't seem too bad, would depend on how fast you can actually do one prefill+full decode run. Say you do it with 10 seconds per iteration/test, then it's only ~10 hours to verify next ten years. Definitely doable.
- eru 2mo agoYou wouldn't need to run all ten years ahead of time. Every Dec 31 you could test out the coming year, if you wanted to.