36 ms·
So this paper appears to have been published on 2017-12-23 (according to https://link.springer.com/chapter/10.1007/978-3-319-70972-7_13 https://link.springer.co
by cscheid 9y ago
So this paper appears to have been published on 2017-12-23 (according to https://link.springer.com/chapter/10.1007/978-3-319-70972-7_13 https://link.springer.com/chapter/10.1007/978-3-319-70972-7_...), which was ahead of the Specter and Meltdown disclosures. Truly unfortunate timing for the browsers implementing mitigation, huh.
It seems that one of the covert channels described here has been fixed (SharedArrayBuffers) but many of the other ones have not. The passive reading of data from timing-based side effects (like CSS animation as described in the paper) seems particularly hard to avoid in general. HTML5 video will have the same vulnerability, I bet.