When it comes to timing attacks in things like decryption or password comparisons, I thought random latency was a pointless addition as it only requires a bit more sampling before you can pull the underlying differences out.
Does it work in this instance just because the numbers involved are a few magnitude less would be with something like network requests?
For 'hardened' browsers I'd recommend a visual indication of this timeout (a pie chart which completes like a clock at a fixed rate while paused is the first concept that I think of).
But this still suppose that the attack is carried over the network. If the attacker can, e.g., monitor the electrical activity of the physical keyboard, then it's another thing entirely.
http://www.securiteam.com/securitynews/5UP0D2AAUK.html
Because of this, it is possible to measure keypress AND key release timings _very precisely_, for any console user of a machine we have an unprivileged account on.
Curious if this has changed recently to warrant this comment as the last course I took was a while ago.
At the start of the course they have you type the phrase once or twice to get your cadence and then take your picture afterwards.