4 ms·
If anything running code in a managed environment would be less vulnerable to timing attacks, given the non-deterministic nature of the garbage collector.
by MagicWishMonkey 12y ago
If anything running code in a managed environment would be less vulnerable to timing attacks, given the non-deterministic nature of the garbage collector.
- Someone1234 12y agoI'm not sure I agree with that either. I'd argue they're both as bad as one another. Since GC is non-deterministic it means you just need more cycles for an accurate result (and plus you're already having to ignore other sources of latency, like network, disk IO, OS lock contention, etc). Timing attacks are generally a coding problems, both a JIT-ed managed codebase and a native block of code can contain them.
- bmm6o 12y agoIf there's timing information leaked by the implementation then non-deterministic interference by things like GC pauses (CPU load, network traffic, etc) are noise that raises the work effort of the attack but does not in general make it impossible. This is why "introduce a random sleep" is a terrible defense to a timing attack. Statistics doesn't care about the cause of the variability, if there are samples coming from different populations it can detect that.
- jamesaguilar 12y ago> terrible defense In what sense? In the sense of not mathematically fixing the problem, or in the sense of leaving it feasible to exploit in reality?
- bmm6o 12y agoBoth, unless I don't understand the distinction you're trying to make. The problem is that the law of large numbers is on the attacker's side. If the attacker gets N tries his statistical power goes as sqrt(N), which means that to stay safe the variance in your random delay has to be large enough to cover that. That is, if d is the timing difference between the slow path and the fast path and the attacker gets N tries, the variance in your random delay has to be on the order of d sqrt(N). This is huge even for modest values of N.