Web timing attacks: super cool in principle, still super janky in practice. Seems like TimeTrial (github.com/dmayer/time_tr…) and Nanown (code.blindspotsecurity.com/trac/nanown/) still best tools, but really janky to get running & require a known-good case. Anyone got suggestions? Banging my head.