Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think it is still discoverable because adding random data leads to the following two distributions:

Attacker gets secret wrong, page is size: original page + (zero to fifty) + length of incorrect secret Attacker gets secret right, page is size: original page + (zero to fifty)

With a sufficiently high number of observations the attack with the right secret has a mean value that is lower than the attack with the incorrect secret.

At least that's what it appears to me. I could be wrong.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: