Re: [TLS] A closer look at ROBOT, BB Attacks, timing attacks in general, and what we can do in TLS

2018-01-08 Thread Colm MacCárthaigh
On Mon, Jan 8, 2018 at 6:29 AM, Hubert Kario wrote: > > except that what we call "sufficiently hard plaintext recovery" is over > triple > of the security margin you're proposing as a workaround here > > 2^40 is doable on a smartphone, now > 2^120 is not doable on a

Re: [TLS] A closer look at ROBOT, BB Attacks, timing attacks in general, and what we can do in TLS

2018-01-08 Thread Hubert Kario
On Thursday, 4 January 2018 20:01:03 CET Colm MacCárthaigh wrote: > On Thu, Jan 4, 2018 at 4:17 AM, Hubert Kario wrote: > > > No, I strongly disagree here. Firstly, frustrating attackers is a good > > > definition of what the goal of security is. Some times increasing costs > >