Switch language한국어
Back to the list

Websites have a new way to spy on visitors: Analyzing their SSD activity

TL;DR AI

Key summary

2 min read
  1. Researchers introduced FROST, a browser side-channel attack that times SSD activity from JavaScript.

  2. By reading a large OPFS file and measuring contention, the site can infer user activity with a trained CNN.

  3. In tests on an M2 Mac, the method could classify open apps or websites; the primitive also worked on Linux.

  4. The attack has not been observed in the wild, but it raises new privacy concerns for browser-based fingerprinting.

Read the original