Timing attacks aren't as simple as often presented. Writers often give a set time for checking each character and ignore all other operations in order to make the issue easy to understand, but most people use this to write off the attack altogether. Surely it can't be that simple.
It isn't trivial to take advantage of timing attacks remotely, but researchers have shown that they are definitely exploitable. [1][2]
[1] https://crypto.stanford.edu/~dabo/papers/ssl-timing.pdf [2] https://www.blackhat.com/docs/us-15/materials/us-15-Morgan-W...
Can they? Do cloud providers typically short circuit routes within their public address space? At least in AWS, this is not the case unless e.g. vpc peering is used.
On second thought, even if the attacker egresses via their internet gateway, the next hop will be pretty close to their victim.
That said, I'm curious as to how well that plays out in the real world, particularly over a noisy connection.
---
But if it is feasible, the best method to defeat it is probably rate-limiting. That then gets tricky. You can rate limit on username alone, IP address alone, or a complex derivative of them (e.g. to detect botnets). But all those approaches introduce their own DDOS and scalability issues.
I've done it before, against a server that deliberately had a vulnerability left on it.
A super-naive approach with no statistical rigor managed to produce usable results at a slow-but-practical rate. Improved technique would have made it faster and less noisy.
The big realization you quickly make is that partial accuracy is good enough to in a vast majority of cases. Sure, 100% accuracy is hard. But 50% accuracy is both surprisingly easy and surprisingly powerful.