Yahoo’s “crypto witch” exploits web security feature, learns your site history

Timing attacks are an interesting part of computer security. As an extreme example, imagine that your computer took one second to verify each character in your login password. And now imagine that it stopped checking at the first wrong character, for reasons of efficiency. You could quickly figure out the right password by timing how […]