This chapter, like Chap. 19, considers timing attacks against RSA decryption — but from a different perspective. Recall that in Chap. 19 decryption is treated as a black box protected only by the “external” defenses of blinding and bucketing, and under a weak observational model that allows the adversary to see only the total amount of time required by a decryption, as might be appropriate if the decryption were done remotely.