Browser-based SSD timing attack reveals open websites and apps (arstechnica.com)
0xBASE INTEL BRIEF
- FROST measures SSD contention via JavaScript and OPFS.
- Identifies which websites and apps are open on the device.
- Requires >1 GB OPFS file; only proof-of-concept so far.
"Researchers have developed FROST, a side-channel attack that uses JavaScript to measure SSD contention via the Origin Private File System (OPFS). By training a convolutional neural network on latency traces, attackers can fingerprint which websites (across browsers) and applications a visitor has open. The attack requires a large OPFS file (≈1 GB) and was demonstrated on macOS and Linux. Mitigations include closing unused tabs or limiting OPFS file size."
#side-channel attack
#browser fingerprinting
#SSD timing
no comments yet.