Mastodon Feed: Post

Mastodon Feed

soatok@furry.engineer ("Soatok Dreamseeker") wrote:

Background

In August 2020, I wrote a guide to side-channel attacks in software: https://soatok.blog/2020/08/27/soatoks-guide-to-side-channel-attacks

I had provided example snippets in PHP and wrote a TypeScript implementation on GitHub called constant-time-js.

https://github.com/soatok/constant-time-js

While at Megaplex, I received an email disclosing a vulnerability in constant-time-js with the V8 JavaScript engine. I've since updated the blog post and tagged v0.5.0 with a fix for the reported leakage.