On 10/24/11 3:56 AM, "Massimiliano Masi"
<> wrote:
>>Unfortunately it's not just error messages (that's easy to prevent), it's
>> also a timing attack.
>>
>
>Yes, that's true. But these attacks are really hard to prevent, AFAIK.
That doesn't make them any less relevant.
>
>Most of the attacks to crypto systems based on oracles, are suffering
>from timing problems. Do you think that the paper from Bochum is
>suggesting
>timing attacks of another kind?
No, but there are workarounds that prevent this specific problem that SAML
can encourage.
-- Scott