Hacker News new | ask | show | jobs
by sroussey 91 days ago
Yeah, though the n^2 is overstating things.

One thing I noticed was that they time each call and then use a median. Sigh. In a browser. :/ With timing attack defenses build into the JS engine.

1 comments

For those of us not in the know, what are we expecting the results of the defenses to be here?
Jitter. It make precise timings unreliable. Time the entire time of 1000 runs and divide by 1000 instead of starting and stopping 1000 timers.