Mit der Technik #FROST können Websites über #JavaScript die #SSD-Aktivität von Besuchern analysieren und so offene Tabs oder Apps erkennen.

Grundlage ist ein sogenannter #SideChannel, der Zeitunterschiede bei Speicherzugriffen im #Browser misst. Dafür wird das Origin Private File System genutzt.

Die Methode gilt als komplex, zeigt aber neue Risiken für den #Datenschutz. Browserhersteller prüfen Gegenmaßnahmen.

https://arstechnica.com/security/2026/05/websites-have-a-new-way-to-spy-on-visitors-analyzing-their-ssd-activity/

#ITSecurity #Tracking #Cybersicherheit

Websites have a new way to spy on visitors: Analyzing their SSD activity

Telltale SSD activity can be measured in the browser using simple JavaScript.

Ars Technica
Websites have a new way to spy on visitors: Analyzing their SSD activity

Telltale SSD activity can be measured in the browser using simple JavaScript.

Ars Technica
Websites Have a New Way To Spy On Visitors: Analyzing Their SSD Activity - Slashdot

An anonymous reader quotes a report from Ars Technica: Now sites have a new way to spy on their visitors: measuring subtle interactions with their solid-state drives. The technique, named FROST (fingerprinting remotely using OPFS-based SSD timing), allows sites to monitor other sites a visitor is vi...

Random thought...

I feel like a #Pcie5 #NVME #SSD could be worth the investment, just for the #OperatingSystem (be it #Linux and its Libraries/Swap or #Windows) and other main-load programs like #Steam and #Firefox (or another #WebBrowser), but the cheapest ones are nearly $200 and they're all at least 1TB... I wonder if we will see cheaper quarter-TB ones in the next couple years, because that feels like it'd be a good way to utilize the PCIe5 NVME slot in my fancy motherboard...

...or I could be wrong: it has been pointed out that PCIe5 drive speeds are mainly only useful for sequential reads, as lookup times create latency comparable to PCIe4, and that makes up the majority of read-time for smaller files. Maybe that can be improved? Maybe Linux distros will implement something that makes core libs load as big blocks? Or we'll have a way to speed up common lookups on the #OS side?

If possible, it'd be good for keeping current-gen #computers relevant over the next decade.

#ComputerHardare #technology

Web browsers can spy on information via SSD access times

IT researchers have demonstrated a side-channel attack called "FROST" where browsers can spy on user behavior via SSD access times.

https://www.heise.de/en/news/Web-browsers-can-spy-on-information-via-SSD-access-times-11312045.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon

#Browser #Datenschutz #IT #JavaScript #Linux #macOS #Security #SSD #news

Web browsers can spy on information via SSD access times

IT researchers have demonstrated a side-channel attack called "FROST" where browsers can spy on user behavior via SSD access times.

heise online
🚀 ¿Buscas un hosting potente y flexible? Los VPS Cloud SSD de IDEI Web ofrecen velocidad y escalabilidad para tus proyectos. Con discos SSD, garantizan un rendimiento óptimo. Ideal para desarrolladores y empresas que necesitan control total. Descubre más sobre sus planes y características. #VPS #CloudHosting #SSD #WebHosting
👉 https://ideihosting.com/vps-cloud-ssd/
Cloud Hosting con SSD en España

Servidores VPS SSD en España con máxima velocidad, seguridad avanzada y escalabilidad al instante. Soporte técnico en español 24/7. ¡Activa tu VPS hoy mismo!

IDEI Hosting | Hosting y VPS Profesionales, Rápidos y Seguros en España

Webbrowser können Informationen durch SSD-Zugriffszeiten ausspähen

IT-Forscher haben mit „FROST“ einen Seitenkanalangriff demonstriert, bei dem Browser über SSD-Zugriffszeiten Informationen über das Nutzerverhalten ausspähen.

https://www.heise.de/news/Webbrowser-koennen-Informationen-durch-SSD-Zugriffszeiten-ausspaehen-11311895.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon

#Browser #Datenschutz #IT #JavaScript #Linux #macOS #Security #SSD #news

Wie SSD-Zugriffszeiten zum digitalen Fingerabdruck werden

IT-Forscher haben mit „FROST“ einen Seitenkanalangriff demonstriert, bei dem Browser über SSD-Zugriffszeiten Informationen über das Nutzerverhalten ausspähen.

heise online

💾 Sandisk rilancia gli SSD SATA mentre i prezzi salgono: il vecchio standard torna utile per upgrade concreti e costi ancora gestibili. #SSD #Sandisk

🔗 https://www.tomshw.it/hardware/sandisk-320-520-ssd-sata-prezzi

Sandisk rispolvera gli SSD SATA mentre i prezzi salgono

I nuovi Sandisk 320 e 520 puntano su formato 2,5 pollici, fino a 4 TB e 560 MB/s, in una fase di rincari per lo storage PC consumer.

Tom's Hardware
Websites have a new way to spy on visitors: Analyzing their SSD activity

Telltale SSD activity can be measured in the browser using simple JavaScript.

Ars Technica

⚡ Gli AI PC stanno per fare un salto: SSD più rapidi per modelli locali, avvii fulminei e workflow senza attese. #AIPC #SSD

🔗 https://www.tomshw.it/hardware/silicon-motion-controller-ssd-14-gbs-ai-pc

Gli AI PC potrebbero presto avere SSD molto più rapidi

SM2524XT è un controller PCIe 5.0 da 6 nm per SSD senza DRAM: promette 14 GB/s e minore latenza nei workload IA locali sugli AI PC.

Tom's Hardware