Earlier quoted context omitted.
> time required to detect the attack Personally I haven't seen much of this done in the real world.
I haven't seen ANY side-channel timing attacks performed in the real world, but that doesn't stop the Security Theater crowd from costing us hundreds of millions of dollars and megatons of unnecessary carbon emissions by slowing everyone's CPU performance on the grounds that everyone's threat model is the same.
Do you expect those who do carry out a successful attack to email you and let you know of their success? Or perhaps you think they'll exploit someone, and follow it up with an academic write-up of how they carried out that exploitation, to be widely published?
While security theatre does exist, it's laughable to write off an entire class of vulnerabilities as theatre.