Mit der Technik #FROST können Websites über #JavaScript die #SSD-Aktivität von Besuchern analysieren und so offene Tabs oder Apps erkennen.

Grundlage ist ein sogenannter #SideChannel, der Zeitunterschiede bei Speicherzugriffen im #Browser misst. Dafür wird das Origin Private File System genutzt.

Die Methode gilt als komplex, zeigt aber neue Risiken für den #Datenschutz. Browserhersteller prüfen Gegenmaßnahmen.

https://arstechnica.com/security/2026/05/websites-have-a-new-way-to-spy-on-visitors-analyzing-their-ssd-activity/

#ITSecurity #Tracking #Cybersicherheit

Websites have a new way to spy on visitors: Analyzing their SSD activity

Telltale SSD activity can be measured in the browser using simple JavaScript.

Ars Technica

Websites have a new way to #spy on visitors: #analyzing their #SSD activity

source: arstechnica.com/security/2026/…

The #attack that #FROST uses is known as a contention side channel, which measures the interaction of various processes all using (or competing for) a given resource. By measuring the timing of certain I/O (input-output) operations of the SSD a #visitor is using, the researchers were able to determine the #websites open in other tabs—even on other browsers—and the apps that were open on the visitor’s device. FROST requires no interaction from the visitor other than opening the site hosting the attack.

#news #web #www #browser #hardware #software #sidechannel #tracking #surveillance #privacy #internet #online #security #problem #computer #surfing #hack #hacker #software #cybersecurity

Websites have a new way to spy on visitors: Analyzing their SSD activity

Telltale SSD activity can be measured in the browser using simple JavaScript.

Ars Technica
Websites have a new way to spy on visitors: Analyzing their SSD activity

Telltale SSD activity can be measured in the browser using simple JavaScript.

Ars Technica
Des chercheurs montrent qu'il est possible d'inférer l'activité d'un visiteur web en analysant les patterns d'accès à son SSD — via le timing des requêtes. Pas de JS malveillant, pas de cookie : juste des effets de bord matériels visibles depuis le navigateur. Le canal caché le plus discret est souvent celui qu'on n'a pas pensé à surveiller. #infosec #sidechannel #privacy
https://arstechnica.com/security/2026/05/websites-have-a-new-way-to-spy-on-visitors-analyzing-their-ssd-activity/
Websites have a new way to spy on visitors: Analyzing their SSD activity

Telltale SSD activity can be measured in the browser using simple JavaScript.

Ars Technica

We replicated the Scatter+Moran attack (ASHES@CCS 2021) and looked for ways to push it further with #AI, on a public masked+shuffled AES-128 dataset, in one afternoon.

✔ Replication in 1h ✔ 33% fewer traces ✔ MIA: 50k to 20k ✔ Full Rust in 2.5s

🔗 https://www.eshard.com/blog/revisiting-masked-aes-side-channel-attack-half-day-ai

#sidechannel #hardware #hardwarehacking #cybersecurity #ai #airesearch

Air gaps don't stop sound.

USAT (Ultrasonic Sub-Audible Trojan) — acoustic covert channel operating at 17–22kHz, inaudible, cross-device, no physical access required.

Full research: researchgate.net/publication/404012350

#infosec #redteam #airgap #sidechannel #acoustics #research

Next in the session was Moghimi et al.'s "DROIDCCT: Cryptographic Compliance Test via Trillion-Scale Measurement" revealing cryptographic flaws at massive Android scale. (https://www.acsac.org/2025/program/final/s267.html) 4/6
#AndroidSecurity #SideChannel

Modern Tale of Blinkenlights

Shows how hardware LED patterns can leak sensitive data, enabling side-channel attacks through optical emissions.

https://blog.quarkslab.com/modern-tale-blinkenlights.html

#SideChannel #Hardware

A modern tale of blinkenlights - Quarkslab's blog

This blog post demonstrates how a modern variant of an hardware attack found in the 2000's allowed the extraction of a €12 smartwatch's firmware using only cheap and robust hardware. Damien and Thomas (introduced later in this post) gave a talk on this subject at this year's leHACK edition in Paris.

Watch this video, https://www.youtube.com/watch?v=_6BcuHpp9eU and vote this person as president. #sydbox denies sysipvc(7) API by default, thank me later: https://man.exherbo.org/syd.7.html#Shared_Memory_Hardening #exherbo #linux #security #sidechannel
#NullconBerlin2025 | Derandomizing Kernel Object Locations w Software Hardware-Induced Side Channels

YouTube

Ich kann meinen Account noch so stark absichern, #MFA, #biometrie, #faceid – es braucht manchmal bloß eine einzige Rechnungsnummer, um Zugang zu erhalten.

https://www.gamepro.de/artikel/psn-account-kann-gehackt-werden-mit-rechnung,3445381.html

Gutes Vergleichsbeispiel, um einen #sidechannel-Angriff auf Software zu erklären, denke ich.

Riesige PSN-Sicherheitslücke entdeckt: Macht ihr nur einen Fehler, kann euer PlayStation-Account gehackt werden - trotz Zwei-Faktor-Authentifizierung

Maßnahmen wie 2FA oder Passkeys sollen euren PSN-Account eigentlich vor Fremdzugriff schützen. Stattdessen reicht eine einfache Rechnung zum Hacken...

GamePro