Listen to the Whispers: Web Timing Attacks that Actually Work
James Kettle
DEF CON 32 Main Stage · Day 1 · Main Stage
Overview
In this compelling DEF CON 32 talk, "Listen to the Whispers: Web Timing Attacks that Actually Work," renowned security researcher James Kettle tackles the notoriously elusive world of web timing attacks. Often relegated to theoretical discussions or highly controlled lab environments, timing attacks have long frustrated practitioners due to the overwhelming "noise" of real-world network conditions. Kettle's research, born from a decade of avoiding this "research trap," reveals how modern web protocols, particularly HTTP/2, have fundamentally shifted the landscape, making these attacks not only viable but broadly applicable against live systems.

Key moments
- 0:00 Introduction: The timing divide, theory vs. reality
- 2:00 Initial failures and the 'timing divide' concept
- 3:00 Defining the 'timing divide' in web attacks
- 4:00 Smallest measurable difference (200us) and talk agenda
- 5:00 Understanding signal and noise in timing attacks
- 5:45 How HTTP/2 eliminates network jitter for attacks
- 6:30 Addressing the 'sticky ordering problem' in HTTP/2
Listen to the Whispers: Web Timing Attacks that Actually Work
Speakers: James Kettle
Conference: DEF CON 32
YouTube: https://www.youtube.com/watch?v=zOPjz-sPyQM
Overview
In this compelling DEF CON 32 talk, "Listen to the Whispers: Web Timing Attacks that Actually Work," renowned security researcher James Kettle tackles the notoriously elusive world of web timing attacks. Often relegated to theoretical discussions or highly controlled lab environments, timing attacks have long frustrated practitioners due to the overwhelming "noise" of real-world network conditions. Kettle's research, born from a decade of avoiding this "research trap," reveals how modern web protocols, particularly HTTP/2, have fundamentally shifted the landscape, making these attacks not only viable but broadly applicable against live systems.
Kettle's presentation delves into a critical divide: the vast chasm between the theoretical potential of timing attacks and their practical utility. He demonstrates how to bridge this gap by meticulously reducing environmental noise, enabling the detection of minute timing differences as small as 200 microseconds (0.2 milliseconds). The talk introduces novel techniques and provides open-source tooling, empowering security professionals to uncover subtle vulnerabilities that were previously undetectable, potentially leading to critical findings like account hijacking on arbitrary websites.
This talk is significant because it redefines the feasibility of a long-understood but rarely-exploited attack class. By proving that web timing attacks can "work everywhere" with "no configuration required," Kettle opens up a new frontier for vulnerability research. His findings, tested on tens of thousands of live websites with bug bounty programs, challenge conventional wisdom and equip defenders with a deeper understanding of a resurging threat.
Background
▶ Watch: Introduction: The timing divide, theory vs. reality (0:00)
Timing attacks operate on the principle that the time an application takes to respond to a request can reveal sensitive information about its internal state or data. For instance, comparing a guessed secret (like a password reset token) character by character might result in slightly longer processing times for each correct character match. In theory, by measuring these tiny time differences, an attacker could infer the secret. James Kettle began his research with precisely this goal: to determine if a target website contained a password reset token with a particular prefix in its database, with the ultimate aim of guessing the full token and hijacking accounts.
However, his initial attempts, like many before him, were met with failure. He tried to replicate a published write-up, only to discover it was purely theoretical, lacking a proof of concept. Building his own vulnerable system yielded no success, and even a third-party lab environment that appeared vulnerable was found to contain an intentionally added "sleep statement" in its string comparison function, artificially inflating the timing difference. A local benchmark involving tens of millions of measurements on his own system also failed to produce reliable results.
These repeated failures hammered home the concept of the "timing divide": the significant gap between the theoretical viability of timing attacks and their practical application in the wild. This divide is unique to web timing attacks, creating a dramatic split between what works in a researcher's head, what works in a contrived lab, and what genuinely works against a live, remote target. The primary culprit for this divide has historically been noise, specifically network jitter and internal jitter. Network jitter, caused by variable network latency, has been notorious for drowning out the subtle "signal" of timing differences, making remote timing attacks seem impossible. The challenge, as Kettle identified, was to find the boundary in this divide – the smallest measurable time difference that could lead to a real finding on a live system, a threshold he ultimately identified as a mere 200 microseconds.
Key Findings
▶ Watch: Defining the 'timing divide' in web attacks (3:00)
James Kettle's research culminates in several pivotal findings that fundamentally transform the landscape of web timing attacks. The most significant is the practical demonstration that these attacks are no longer theoretical curiosities but potent tools capable of exploiting live systems. He achieved this by systematically addressing the pervasive issue of noise that has historically plagued timing attacks.
Firstly, Kettle validated and significantly enhanced the technique of leveraging HTTP/2's concurrency features to effectively eliminate network jitter. This crucial advancement, building upon previous research like the "Timeless Timing Attacks" paper, means that web timing attacks can now be conducted as if the attacker were "effectively local" to the target server, drastically improving the signal-to-noise ratio.
Secondly, he refined the HTTP/2-based approach by overcoming the "sticky ordering problem," a subtle bias in web servers to process the first request in a multiplexed stream before others. While previous work attempted to mitigate this with artificial delays, Kettle's improvements made the technique robust and suitable for use "in the wild on arbitrary targets," without requiring specific target configuration.
Thirdly, his research established a new practical threshold for detectable timing differences: 200 microseconds (0.2 milliseconds or 0.0002 seconds). This incredibly small window demonstrates the precision achievable with his refined methodology, proving that even minute processing variations can be reliably measured and exploited.
Finally, the talk promises the introduction of three novel timing attack techniques, each rigorously tested on "tens of thousands of live websites with bug bounty programs." These techniques are accompanied by "real life case studies" and supported by "free automated open source tooling," designed to empower other security researchers and penetration testers to apply these advanced methods. While the specific details of these three novel techniques are not elaborated upon in the provided transcript excerpt, their existence and proven efficacy on a large scale represent a major contribution to the field of web security.
Technical Deep Dive
▶ Watch: Smallest measurable difference (200us) and talk agenda (4:00)
The success of any timing attack hinges on the delicate balance between signal and noise. The signal is the measurable delay caused by the target application's internal processing logic, such as a character-by-character string comparison. Noise, on the other hand, encompasses all other factors that affect response time, obscuring the signal. Kettle categorizes noise into two primary components: network jitter and internal jitter.
Network jitter refers to the variable latency and packet loss inherent in network communication. Historically, this has been the most significant impediment to remote timing attacks, causing response times to fluctuate wildly and rendering minute timing differences undetectable. The speaker emphasizes that for many years, the common wisdom was that timing attacks demonstrated on local systems would "never work on a remote target" precisely because of network jitter.
However, the advent of HTTP/2 has provided a revolutionary solution to this problem. Kettle highlights the findings of a paper titled "Timeless Timing Attacks," which demonstrated how HTTP/2's concurrency features can be leveraged to effectively eliminate network jitter. HTTP/2 allows multiple requests and responses to be interleaved on a single TCP connection and TLS record through a mechanism known as stream multiplexing. By sending two specially crafted requests within the same TCP packet or TLS record, the server is compelled to process them almost simultaneously. Crucially, because both requests traverse the same network path and are processed by the server in close proximity, any network-induced delay or jitter affects both requests equally. By comparing the processing times of these co-located requests, the attacker can effectively subtract out the network noise, isolating the internal processing time difference. This technique renders web timing attacks "effectively now local," even when targeting remote servers.
While the "Timeless Timing Attacks" paper laid the groundwork, Kettle identified a critical practical challenge: the sticky ordering problem. Despite HTTP/2's concurrency, web servers and underlying application frameworks often exhibit a bias towards processing the first request received on a stream before subsequent ones. This "sticky ordering" can introduce a subtle, consistent delay that complicates precise timing measurements, especially when the signal being sought is extremely small. The original authors of "Timeless Timing Attacks" attempted to address this by adding extra, artificial query parameters to the first request, aiming to make it take longer to process and thus synchronize with the second request.
James Kettle, however, found that this approach had "issues which make it unsuitable for use in the wild on arbitrary targets." While the specific details of his improved solution are not provided in the transcript excerpt, he states that his research has refined this technique, making it robust and universally applicable without requiring specific server-side configurations. This enhancement is crucial for enabling timing attacks to work "everywhere" and on "arbitrary systems."
The ability to effectively neutralize network jitter and mitigate sticky ordering issues has allowed Kettle to push the boundaries of detectable timing differences. His research demonstrates successful findings on live systems with a time difference as small as 200 microseconds (0.2 milliseconds). This incredibly fine-grained measurement capability opens up a vast new attack surface, as even minor variations in server-side logic (e.g., database queries, string comparisons, cache lookups, or file system operations) can introduce delays of this magnitude. The talk promises the introduction of three novel timing attack techniques that leverage this newfound precision, tested on tens of thousands of bug bounty programs, though the specific mechanisms of these techniques are not detailed in the provided transcript. The implication is that these techniques exploit common web application behaviors that, when combined with the low-noise measurement environment, reveal critical information.
Demo / Proof of Concept
▶ Watch: How HTTP/2 eliminates network jitter for attacks (5:45)
While James Kettle's talk strongly emphasizes the practical applicability of his findings, mentioning "real life case studies" and "free automated open source tooling," the provided transcript excerpt does not detail a specific live demonstration or proof of concept. The speaker indicates that the techniques have been tested on "tens of thousands of live websites with bug bounty programs" and that tooling is available to equip attendees to apply these techniques themselves. However, the exact steps, target application, or specific vulnerability exploited in a demo are not described within this portion of the talk.
Defensive Implications
▶ Watch: Addressing the 'sticky ordering problem' in HTTP/2 (6:30)
The transcript mentions that the talk will "talk about defense" towards its conclusion. However, the provided excerpt does not contain specific recommendations or strategies for defending against the advanced timing attacks discussed. Given the nature of timing attacks, general defensive principles would typically include:
- Constant-Time Operations: Implementing all security-sensitive operations, particularly cryptographic functions, string comparisons for secrets (like passwords or tokens), and database lookups that handle sensitive identifiers, in a constant-time manner. This means the execution time should not vary based on the input data or whether a match is found.
- Adding Random Delays: Introducing small, random delays to responses for sensitive operations can help obscure legitimate timing differences. However, this must be done carefully to avoid negatively impacting user experience or creating new vulnerabilities.
- Standardizing Response Times: For critical endpoints, ensuring that all responses, regardless of success or failure (e.g., user not found vs. incorrect password), take approximately the same amount of time.
- Monitoring and Alerting: Implementing robust logging and monitoring to detect unusually high request rates or suspicious patterns of requests that might indicate an attacker attempting to perform timing measurements.
- Reviewing HTTP/2 Implementations: Developers and infrastructure teams should be aware of how their HTTP/2 configurations might facilitate or mitigate timing attacks, particularly regarding request processing order and multiplexing.
- Secure String Comparison Functions: Using language-specific, cryptographically secure string comparison functions (e.g.,
hash_equals()in PHP,timingSafeEqual()in Node.js) that prevent early exit on mismatch.
Without specific defensive guidance from the speaker in the provided transcript, these remain general best practices for mitigating timing attacks.
Key Takeaways
- Timing attacks are no longer theoretical: James Kettle's research demonstrates that web timing attacks are practically viable against remote, live systems, overcoming historical limitations.
- HTTP/2 is a game-changer: The concurrency features of HTTP/2 effectively eliminate network jitter, making remote timing measurements as precise as local ones, especially when combined with careful request structuring.
- The "sticky ordering problem" is solvable: Kettle refined existing HTTP/2 techniques to address server biases, making timing attacks universally applicable "in the wild on arbitrary targets."
- Microsecond precision is achievable: Attackers can reliably detect timing differences as small as 200 microseconds (0.2 milliseconds), opening up a vast new attack surface.
- Novel techniques and tooling are available: The talk introduces three new timing attack techniques and associated open-source tools, validated on tens of thousands of bug bounty programs, making these advanced attacks accessible to a broader audience.
- The "timing divide" is shrinking: The gap between theoretical and practical timing attacks is closing, requiring renewed attention from both attackers and defenders.
About the Speaker(s)
James Kettle is a distinguished security researcher who has dedicated significant effort to exploring the often-overlooked area of web timing attacks. His work, as presented at DEF CON 32, highlights his persistence in challenging established norms and pushing the boundaries of what is considered exploitable in web security. While the provided metadata does not specify his exact title or company, his research demonstrates a deep expertise in web application vulnerabilities and a commitment to developing practical, real-world attack techniques and defensive strategies. He is known for his analytical approach and his ability to translate complex theoretical concepts into actionable security insights. (Note: The speaker mentioned his baby daughter arrived six weeks early the morning before the talk, providing a personal context for his virtual presentation.)
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
James Kettle's research fundamentally redefines the viability of web timing attacks, pushing them from theoretical curiosities to practical, real-world exploits. By meticulously addressing network and internal jitter through refined HTTP/2 techniques, he demonstrates how to achieve microsecond precision on live systems. This talk is a critical advancement, providing novel techniques and open-source tooling that will undoubtedly open a new frontier for vulnerability research and force defenders to reassess their threat models.
Heather Calloway (CISO) — STRONG ACCEPT
James Kettle's research fundamentally shifts the understanding of web timing attacks, moving them from theoretical curiosities to proven, practical threats. By demonstrating how HTTP/2 effectively neutralizes network noise and enables microsecond precision, he exposes a significant, previously underestimated attack surface. This work demands immediate attention from security leadership to re-evaluate risk, update vulnerability management strategies, and ensure engineering teams understand the implications of constant-time operations and secure HTTP/2 configurations. While excellent in demonstrating the attack vector and providing tools for discovery, the provided text is light on specific…