What Happens When a Computer's Clock Is Off by Just One Second
Your PC or smartphone's clock appears remarkably accurate. However, a computer's built-in clock runs on a crystal oscillator, and left alone it drifts by several seconds a day. If left uncorrected, TLS certificate verification fails, two-factor authentication one-time passwords become invalid, log timestamps become unreliable, and distributed system data integrity collapses.
NTP (Network Time Protocol) is the protocol that corrects this "clock drift" over the internet.
NTP - A Protocol Keeping Time Since 1985
NTP was designed by David L. Mills, and its first specification, RFC 958, was published in September 1985. It has been revised several times since; NTPv4, defined in RFC 5905 (2010), is the version in widespread use. NTP operates using a hierarchical structure called Stratum.
- Stratum 0: High-precision time sources such as atomic clocks and GPS receivers. Not directly connected to the network
- Stratum 1: NTP servers directly connected to Stratum 0. Known as "primary reference clocks"
- Stratum 2: Servers that obtain time from Stratum 1. Many public NTP servers operate at this level
- Stratum 3 and beyond: Servers that sequentially obtain time from lower-tier servers. Maximum of Stratum 15
NTP doesn't simply copy the server's time - it measures and compensates for network latency. It obtains time from multiple servers and uses an algorithm that statistically selects the most reliable value.
What Breaks When the Clock Is Off
TLS Certificate Verification
TLS certificates have a validity period (Not Before / Not After). If the client's clock is significantly off, it may judge a valid certificate as "expired" or an not-yet-valid certificate as "valid." The Certificate Transparency mechanism also depends on accurate time.
TOTP (Time-Based One-Time Passwords)
Authenticator apps like Google Authenticator generate codes that change every 30 seconds based on the current time. The specification (RFC 6238) allows verifiers to accept roughly one step (30 seconds) of slack to absorb network delay, so a small drift still gets through. Once the gap exceeds that allowance, however, even a correctly typed code will not match and login fails.
Kerberos Authentication
Kerberos authentication, used in Active Directory, does not tolerate clock differences of more than 5 minutes by default. If NTP goes down on a corporate network, every employee can be locked out.
Distributed Databases
Distributed databases like Google Spanner determine transaction ordering by time. Google built a time infrastructure called TrueTime that combines atomic clocks and GPS, and exposes time not as a single point but as an interval that includes its own margin of error. Rather than eliminating drift, it guarantees an upper bound on drift and preserves transaction ordering within that bound.
Log Reliability
When investigating security incidents, logs from multiple servers are correlated chronologically. If clocks are out of sync, the causal relationships between events cannot be accurately reconstructed.
Leap Seconds - Time Synchronization's Greatest Enemy
Because the Earth's rotation speed isn't constant, a gap slowly opens between time accumulated from the uniform seconds of atomic clocks and time based on the Earth's rotation (UT1). To keep that gap within a fixed range, "leap seconds" are occasionally inserted into the UTC we all use: a normally nonexistent second, 23:59:60, is added after 23:59:59.
When the leap second was inserted on 30 June 2012, a flaw in the Linux kernel's leap second handling triggered a wave of outages at services running on Linux, including Reddit and Mozilla. Much software assumed "a minute has 60 seconds" and didn't account for a 61st second.
In response, Google developed a technique called "leap smear." Instead of inserting the leap second all at once, it gradually adjusts the time over 24 hours. In 2022, Resolution 4 of the General Conference on Weights and Measures (CGPM) decided to raise the tolerance for the difference between UT1 and UTC by 2035, which in practice means an end to inserting leap seconds.
Summary
Time synchronization is one of the most unglamorous pieces of the internet's "invisible infrastructure," yet its importance is immeasurable. TLS, 2FA, Kerberos, distributed databases, log analysis - all of these depend on accurate time. When you check your connection information on IP Check-san, the TLS handshake powering that communication also relies on precise time synchronization.
Related Terms in This Article
Frequently Asked Questions
What is NTP?
NTP (Network Time Protocol) has synchronized clocks across computer networks since its first specification, RFC 958, was published in 1985. It uses a hierarchical system of time sources called Strata, with atomic clocks at Stratum 0 and each subsequent level slightly less accurate.
What breaks when the clock is wrong?
TLS certificates are rejected if the system clock is outside their validity period. TOTP two-factor authentication codes fail once the clock gap exceeds the slack the verifier allows, which is typically one 30 second step. Kerberos authentication rejects tickets with more than 5 minutes of clock skew. Distributed databases can produce inconsistent results.
What is a leap second?
A leap second is a one-second adjustment added to UTC to keep it aligned with Earth's slowing rotation. Leap seconds have caused notable incidents, including a 2012 Linux kernel bug that took down services running on Linux such as Reddit and Mozilla. In 2022 the General Conference on Weights and Measures decided to stop inserting leap seconds by 2035.