river-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Peter Firmstone <j...@zeus.net.au>
Subject Interesting article on encryption timing attacks.
Date Sun, 19 Jun 2011 11:21:13 GMT
http://codahale.com/a-lesson-in-timing-attacks/

The lesson is verifying hash codes etc should be in constant time, don't 
return early.

Hmm, an Executor, with a Future, could be used to process / compare 
sensitive data, the submitting thread could sleep for a constant period, 
then wake up & get the result.

Cheers,

Peter.

Mime
View raw message