Your SSD Can Now Leak Your Browsing Habits to Websites

A newly uncovered technique called FROST lets websites spy on you by measuring how your solid-state drive responds to data requests. Researchers have shown that a simple webpage, with no extra permissions, can figure out which other sites you have open and what applications are running on your machine. The method exploits a side channel in the browser's origin private file system (OPFS), a storage area that any site can create without asking. By timing how long it takes to read a large file from the SSD, a JavaScript script can detect contention caused by other processes accessing the drive. Those timing patterns are then fed into a pretrained neural network, which classifies the activity—matching it to known websites or apps. The attack works across different browsers and requires nothing from the visitor beyond opening the malicious page. There are caveats: the OPFS file needs to be huge, often over a gigabyte, which makes mass surveillance impractical and detectable. Also, the technique only works if the OPFS file and the target apps share the same physical SSD. Closing tabs you don't need is the simplest defense. Browser makers could also limit the maximum OPFS file size to block the attack. The researchers, who tested the full attack on macOS and the underlying timing primitive on Linux, have not seen evidence of FROST being used in the wild. Their findings are slated for presentation at the DIMVA conference in July.
Source: Wired
dArt Studio installs AI for local businesses in Broward & Palm Beach County, FL. We reply within 1 business hour.