Skip to content
Better HN
Top
Best
Ask
Show
New
Jobs
Search
⌘K
Timing Side-Channel for SQL SELECT WHERE (?)
(opens in new tab)
(altayakkus.substack.com)
2 points
biosboiii
1y ago
1 comments
Save
Share
1 comments
1 comments · 1 top-level
top
newest
oldest
biosboiii
OP
1y ago
I don't want to clickbait, but I went down a rabbithole of answering my question if the timing of a SQL query, comparing to a string, can be used as a side-channel to more efficiently guess that string.
tl;dr is No. Enjoy :)
j
/
k
navigate · click thread line to collapse