Websites have a new way to spy on visitors: analyzing their SSD activity
ID: 8c2d211f-abd2-510b-897a-d0c6ce3770ca
STIX ID: report--8c2d211f-abd2-510b-897a-d0c6ce3770ca
Feed Name: Security - Ars Technica
Researchers describe "FROST," a proof-of-concept browser-based side-channel that uses a large Origin-Private File System (OPFS) file and JavaScript to measure SSD access contention; a convolutional neural network trained on these latency traces can fingerprint active applications and websites. The attack was fully demonstrated on an M2 Mac (Linux primitive tested), has practical limitations (requires gigabyte-scale OPFS files on the same SSD, detectable at scale), no reported real-world usage, and the paper recommends mitigations such as limiting OPFS file sizes and closing unused tabs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
