[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Timing Cryptanalysis Attack



Hey, don't go for constant time, that's too hard to get perfect.  Add a
*random* delay.  This particular crypto-flaw is pretty easy to fix. 
(See, I'm not *always* arguing the downside of cryptography!)

It is worth noting, however, the extent to which "secure" cryptographic
protocols keep needing to get fixed one last time....  -- Nathaniel
--------
Nathaniel Borenstein <[email protected]>       | (Tense Hot Alien In Barn)
Chief Scientist, First Virtual Holdings | VIRTUAL YELLOW RIBBON:
FAQ & PGP key: [email protected]       | http://www.netresponse.com/zldf