▲ | jack_pp a year ago | |||||||
or you could benchmark the functions that compare secrets to user input and figure out how much time it's supposed to take, add 0.5s to the average and always add time before responding to get to that target so essentially your response time is constant regardless of input | ||||||||
▲ | tptacek a year ago | parent [-] | |||||||
Important to keep in mind here that the timing attacks Kettle is talking about generally do not take the form of "providing secret input to a function with variable timing". | ||||||||
|