Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Side-channel timing attacks work on websites by executing MANY similar requests. In a similar way, in this case, while individual requests may not appear to adhere to a timing profile, over time they likely will still be discoverable.

c.f. The random number generator in "The Mythical Man Month" that only guaranteed any one number will be random, not a sequence of numbers.



Makes sense. But man these attacks really do need lots and lots of CPU just to extract one bit of data.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: