Over the decades, there has been no shortage of sites using clever techniques to covertly track visitors’ browsing histories, device fingerprints, and keystrokes and mouse movements in real time. Even Meta and Yandex were recently caught joining in the privacy-invasive free-for-all.
Now sites have a new way to spy on their visitors: measuring subtle interactions with their solid-state drives. The technique, named FROST (fingerprinting remotely using OPFS-based SSD timing), allows sites to monitor other sites a visitor is viewing and what apps are open on their devices.
A side channel based on contention
The technique, laid out in a research paper, exploits a side channel, a form of leak resulting from physical manifestations such as electromagnetic emanations, data caches, or the time required to complete a task. By measuring the manifestations, attackers can decrypt encrypted traffic and infer other confidential data.Read full article
Comments
Google I/O大会上,AI生成答案成为搜索引擎核心功能,颠覆了传统“十条蓝色链接”的营销模式。品牌方无法掌控AI如何描述自身形象,其“黑箱”特性导致不可控风险,如负面评论可能影响AI输出。这一“零点击搜索”趋势冲击广告点击和流量分发,迫使数字广告生态系统重构。专家建议品牌转向声誉管理、结构化数据和知识图谱技术,并预测AI品牌管理师等新职业将出现。适应AI主导的搜索环境已成为企业生存的关键。