- * y and y^d; then we multiply x by y, raise to the power e mod
- * n as usual, and divide by y^d to recover x^d. Thus the
- * timing of the modpow does not reveal information about x,
- * but only about xy, which is unpredictable to an attacker.
+ * y and y^d; then we multiply x by y, raise to the power d mod
+ * n as usual, and divide by y^d to recover x^d. Thus an
+ * attacker can't correlate the timing of the modpow with the
+ * input, because they don't know anything about the number
+ * that was input to the actual modpow.