Forgot your password?
typodupeerror

Comment All data should be fuzzed by the browser (Score 3, Insightful) 110

There should be no such thing as accurate timing from any API the browser provides, by default.

If there is a site that requires this type of accurate timing information, an exception should be able to be created, but it should be off by default.

We just keep seeing these timing attacks. There is just no reason a random web site needs accurate information from your browser to function.

Slashdot Top Deals

"A child is a person who can't understand why someone would give away a perfectly good kitten." -- Doug Larson

Working...