The V8 JavaScript Runtime Undermined My Constant-Time JavaScript Library 0 ▲ Dhole Moments 1 hour ago · 17 min read3435 words · Tech · hide · 0 comments Six years ago, I wrote a blog post titled Soatok’s Guide to Side-Channel Attacks in which I discussed the general topic of side-channels in cryptographic applications, and how to avoid them, with example code in PHP. I had called out that the algorithms discussed on the page cannot rule out compiler or runtime optimizations that undermine your security goals: You can achieve algorithmic constant-time, but any higher assurance was outside the scope of the work being done. For that reason, we’re going to assume that algorithmic constant-time is adequate for the duration of this blog post. If your threat model prevents you from accepting this assumption, feel free to put in the extra effort yourself and tell me how it goes. After all, as a furry who writes blog posts in my spare time for fun, I don’t exactly have the budget for massive research projects in formal verification. Soatok’s Guide to Side-Channel Attacks (Aug. 2020) To make it easier to see in action, I also wrote a separate… No comments yet. Log in to reply on the Fediverse. Comments will appear here.