This repository was archived by the owner on Mar 20, 2025. It is now read-only.
OMEMO - Timing Side-Channel in HMAC ComparisonΒ #646
Open
Description
Originally disclosed here.
qxmpp/src/omemo/QXmppOmemoManager_p.cpp
Line 1766 in 94232e7
Explainers:
- https://soatok.blog/2020/08/27/soatoks-guide-to-side-channel-attacks/
- https://security.stackexchange.com/a/74552
This defect is a problem with the OMEMO specification. It should have called out the specific steps that implementors follow to prevent this sort of side-channel attack.