Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

http://codahale.com/a-lesson-in-timing-attacks/

Suggests 20us over internet, 100ns over lan. Are there more complexities to comparing HMACs than are mentioned in this article? I.e. anything else to think about other than not short-circuiting your comparisons when bytes don't match?

More discussion (including from someone called Nate, presumably the same person tptacek is referring to) at:

http://groups.google.com/group/keyczar-discuss/browse_thread...

And a paper which I can't read without paying:

http://www.computer.org/portal/web/csdl/doi/10.1109/MSP.2009...




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: