• Buddahriffic@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    21 hours ago

    Sounds like a bunch of timing attacks could be rendered useless if access to an accurate timer required special permission. And without the permission, it either limited the resolution or added random jitter to any timer APIs.

    • bitfucker@programming.dev
      link
      fedilink
      English
      arrow-up
      2
      ·
      11 hours ago

      Yeah, honestly we should have a way to instrument JS without actually making the JS runtime able to read the measurement data