logo

Constant-Time Data Processing & QUIC Privacy

ID: 82cd78f6-f09c-5fd1-82cc-4e6c49925710

STIX ID: report--82cd78f6-f09c-5fd1-82cc-4e6c49925710

Feed Name: NCC Research

Threat Score
20/100

Date Published: 2026-05-13

Date Updated: 2026-07-31

...
...

NCC Group Cryptography Services analyzed QUIC implementations and found recurrent timing side channels caused by processing data that begins at a secret offset (e.g., variable-length QUIC packet numbers). The report explains the leakage risk (revealing packet number length and inferred payload size), presents constant-time primitives and full proof-of-concept code in Rust and Common Lisp to extract/process data at secret offsets without branching, and discusses practical costs, limitations, and deployment considerations for maintaining constant-time behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.