Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> If it's off doing anything else that I can observe, then I can time that instead. And we're back to square one.

Wouldn't these kinds of leaks always be present though? The scheduler can swap your process out at any time, regardless of whether it explicitly calls sleep() or not, so even with a constant time algorithm you'll have some variability.



The problem isn't variability in total.

The problem is variability based on a secret input.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: