3 ms·
Woah! Summarizing: ... Goethem et al. exploited more accurate in-browser timing to obtain information even from within other websites, such as contact lists
by benjaminjackman 9y ago
Woah!
Summarizing:
...
Goethem et al.
exploited more accurate in-browser timing to obtain information even from within other websites, such as contact lists or previous inputs.
...
Oren et al. recently demonstrated that cache side-channel attacks can also be performed in browsers. Their attack uses the performance.now method to obtain a timestamp whose resolution is in the range of nanoseconds. It allows spying on user activities but also building a covert channel with a process running on the system. Gruss et al. and Bosman et al. demonstrated Rowhammer
attacks in JavaScript, leveraging the same timing interface. In response, the WC and browser vendors have changed the performance.now method to a resolution of 5 µs. The timestamps in the Tor browser are even more coarse-grained, at 100 ms .
In both cases, this successfully stops side-channel attacks by withholding necessary information from an adversary.
In this paper, we demonstrate that reducing the resolution of timing information or even removing these interfaces is completely insucient as an attack mitigation.
...
Our key contributions are:
– We performed a comprehensive evaluation of known and new mechanisms to obtain timestamps. We compared methods on the major browsers on Windows, Linux and Mac OS X, as well as on Tor browser.
– Our new timing methods increase the resolution of ocial methods by 3 to 4 orders of magnitude on all browsers, and by 8 (!!) orders of magnitude on Tor browser. Our evaluation therefore shows that reducing the resolution of timer interfaces does not mitigate any attack.
– We demonstrate the first DRAM-based side channel in JavaScript to exfiltrate data from a highly restricted execution environment inside a VM with no network interfaces.
– Our results underline that quick-fix mitigations are dangerous, as they can establish a false sense of security.
- ocfx 9y agoELI5 how having a timestamp with resolution in the range of nanoseconds allows spying on user activities and how they are actually accessing performance.now in a user's session (ad? extension?)
- pdkl95 9y ago> reducing the resolution of timer interfaces does not mitigate any attack. > quick-fix mitigations are dangerous, as they can establish a false sense of security. This demonstrates - again - the danger of treating security as default-permit. This blacklist-style thinking is very common, but it is guaranteeing eventual failure because you cannot enumerating badness[1]. Limiting the granularity of performance.now assumes that providing any timing information at all is safe. It's the same basic misunderstanding of what it means to design for security I hear way too often whenever a new security issue is being discussed: someone always asks "Is this an actual problem in the wild, or whining about some hypothetical that isn't a 'real threat'?" So what; future threats are nt limited to only the attacks we know about today. As I sain in a recent comment[2], the thing that nobody really wants to talk about is that it isn't possible to know the behavior of programs a Turing complete language without running the program. Declarative documents in HTML+CSS were safe, but trying to run potentially malicious Turing complete programs safely is provably futile endeavor. [1] http://www.ranum.com/security/computer_security/editorials/dumb/ http://www.ranum.com/security/computer_security/editorials/d... [2] https://news.ycombinator.com/item?id=15708099 https://news.ycombinator.com/item?id=15708099