|
|
|
|
|
by TylerE
1302 days ago
|
|
Don’t really buy it. Seems to be both “spherical cow optimistic assumptions” and “anyone who could seriously think about pulling this off has nation-state level resources and already 0wnz you and/or already has the rubber hose at hand" |
|
Also ignoring the fact that calling constant_strcompare(string, string) instead of strcompare(string, string) when working with secrets isn't that big of an ask.
[0] https://crypto.stanford.edu/~dabo/papers/ssl-timing.pdf