@newt @sun i too felt the timing attack was hyperbole. just because a vector is possible doesn't mean it's probable. it's sort of like when sudo was rekt. if someone has remote access on my machine via ssh or some sort of breakout from a pid then i deserve what i have coming to me, the bigger problem being my access control and ids/ips system vs sudo being broke.
a balance of paranoia and practicality always worked well for me.