V8 JIT Optimizations Break Constant-Time Guarantees in JS Crypto Library
jedisct1 · x · 2026-09-12
Security blogger Soatok discloses that PhD student Yayu Wang found a side-channel in constant-time-js: V8's JIT compilation can compile key-dependent code and undermine algorithmic constant-time design. The author had long warned compiler/runtime optimizations can defeat such guarantees, kept the library demo-only, and has shipped a 0.5.0 fix.
Related event: V8 optimizations break constant-time crypto in JavaScript(2 posts)→
More from Safety
- Dario Amodei calls for frontier AI pacing; Anthropic opens systems to third-party evaluators — dhadfieldmenell · 2026-09-13
- Investor argues frontier AI 'pacing' is unmeasurable; real safety lies in guardrails, not regulation — firstadopter · 2026-09-13
- Sam Altman backs Dario's frontier pacing call, pledges independent evaluators — but logits access history resurfaces — MaziyarPanahi · 2026-09-13
- Researchers: AI developers must show real-life benefits to earn trust — dhadfieldmenell · 2026-09-13
- Bind agent approvals to proposal hashes: any change should invalidate them — arthaudm · 2026-09-13
- Timnit Gebru: AI firms hype extinction fears to dodge real harms like autonomous weapons — SatelliteNetSec · 2026-09-13