Websites have a new way to spy on visitors: Analyzing their SSD activity

TL;DR AI
2 min readKey summary
Researchers introduced FROST, a browser side-channel attack that times SSD activity from JavaScript.
By reading a large OPFS file and measuring contention, the site can infer user activity with a trained CNN.
In tests on an M2 Mac, the method could classify open apps or websites; the primitive also worked on Linux.
The attack has not been observed in the wild, but it raises new privacy concerns for browser-based fingerprinting.
