PulseAugur
中
实时 01:10:31
English(EN) Researchers say they can spy on your browsing by measuring SSD activity through a browser API — claim FROST attack requires no permissions or user interaction to identify which apps and websites you're using

新的FROST攻击通过浏览器API利用SSD活动监视浏览

安全研究人员开发了一种名为FROST的新型侧信道攻击,该攻击可以通过浏览器中的JavaScript测量SSD访问延迟来监视用户的浏览活动并识别打开的应用程序。该技术利用了Origin Private File System (OPFS) API,允许恶意网站在用户的SSD上创建大文件,并分析由此产生的时序模式以推断用户行为。虽然在测试Mac上具有高准确性,但该攻击的主要障碍是大文件大小,提出的缓解措施包括限制OPFS文件大小或要求创建文件的显式权限。 AI

影响 此攻击突显了Web浏览器中新的隐私风险,可能影响用户信任并需要新的安全措施。

排序理由 该集群描述了一种新的攻击技术,该技术在研究论文中有详细介绍,并对浏览器安全产生了影响。

在 Tom's Hardware 阅读 →

AI 生成摘要 · Google Gemini · 来自 3 个来源。 我们如何撰写摘要 →

新的FROST攻击通过浏览器API利用SSD活动监视浏览

本文如何被排名

Signal score
0 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Research
该集群描述了一种新的攻击技术,该技术在研究论文中有详细介绍,并对浏览器安全产生了影响。
Source corroboration
3 independent sources
Multiple independent publishers reporting the same story raises confidence that it's real and newsworthy.
Topics
safety, product, paper
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
128 days old
Aged out of breaking-news scoring windows; ranking reflects the durable signal from the full source set.

完整方法见我们的编辑标准。

报道来源 [3]

  1. Tom's Hardware TIER_1 English(EN) · Luke James ·

    研究人员称,他们可以通过浏览器API测量SSD活动来监视您的浏览 — 声称FROST攻击无需权限或用户交互即可识别您正在使用的应用程序和网站

    FROST exploits the Origin Private File System (OPFS), a browser API that lets websites create and store files on a user's local disk.

  2. Mastodon — fosstodon.org TIER_1 English(EN) · [email protected] ·

    📰 网站现在可以通过硬盘监视你,得益于新披露的FROST技术,浏览器可以测量SSD活动中的蛛丝马迹

    📰 Websites Can Now Spy on You Through Your Hard Drive Thanks to the newly detailed FROST technique, telltale SSD activity can be measured in the browser using simple JavaScript. 📰 Source: Feed: All Latest 🔗 Archive: https://web.archive.org/web/https://www.wired.com/story/websites…

  3. Mastodon — fosstodon.org TIER_1 English(EN) · [email protected] ·

    研究人员称,他们可以通过浏览器API测量SSD活动来监视您的浏览活动——声称FROST攻击无需权限或用户交互

    Researchers say they can spy on your browsing by measuring SSD activity through a browser API — claim FROST attack requires no permissions or user interaction to identify which apps and websit… FROST exploits the Origin Private File System (OPFS), a browser API that lets websites…