Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't think I need to control your clock when I can just look at my watch and know what your clock says. Why do things the hard way?


Because any cryptographic implementation worth its salt wouldn't be using even second resolution time, so what your watch says is irrelevant. Also, if I cracked an NTP feed, I'd not use it to know what the server's clock is set to so much as to manipulate the server's clock to all kinds of wonderful effect.


You're misunderstanding the attack vector. The exploit is about precisely controlling the delta between a client and server.

There is no problem with using low-resolution time signatures as a cryptographic seed. Using time as an entropy source is only a problem if you sample at a lower resolution than your clock's error rate.


Maybe I wasn't clear, but I was thinking one would manipulate the delta specifically to cause the machine to adjust its clock.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: