Earlier quoted context omitted.
For one request, yes. For statistical analysis of many requests, no. People keep extracting secrets from very noisy and weak signals.
In lab conditions, yes. In this case: "Our attack is practical; an unoptimized version recovers the full key from a CIRCL server in 36 hours and from a PQCrypto-SIDH server in 89 hours ... The target server and the attacker are both connected to the same network, and we measure an average round-trip time of 688 µs between the two machines." Note that: • The server in this case does absolutely nothing except use the c…
I feel like if this had been exploited in the wild you would have already heard stories of people using it to zark someone's bitcoin off a Digital Ocean or Vultr node.