Jan. 15, 2013
9:21 a.m.
ok so constant time to answer is better. Stef On Jan 15, 2013, at 9:16 AM, Henrik Sperre Johansen wrote:
On 14.01.2013 22:38, Stéphane Ducasse wrote:
Thanks for sending us this link. It is quite interesting.
Did the people think about using random generated number to change the response time? Network latency, processor scheduling etc. already add a measure of randomness to the returned values, so the attack already presumes you are able to induce the actual signal from noisy results. Adding another random factor doesn't really change that, it just means one would have to adjust how the actual signal is extracted.
Cheers, Henry