3 ms·
That sounds like a fun new fingerprinting attack surface. --- EDIT: That might have been too cynical. Let me take another stab: That opens up some cool new p
by runlevel1 3y ago
That sounds like a fun new fingerprinting attack surface.
---
EDIT: That might have been too cynical. Let me take another stab:
That opens up some cool new possibilities, but also a seemingly large new attack surface.
Does anyone know what's been done to mitigate it?
- sebazzz 3y agoAlso another GPU driver attack vector.
- cubefox 3y agoI'm also excited about WebGPU!
- runlevel1 3y agoTo partially answer my own question, some of the risks are identified here: https://www.w3.org/TR/webgpu/#malicious-use https://www.w3.org/TR/webgpu/#malicious-use The mitigations, however, feel rather light given the exposure.
- cubefox 3y agoThe alternative would be to ask for explicit permission per website, similar to notifications or webcam access. Sounds like overkill to me.
- lxgr 3y agoMalicious/non-informed cryptocurrency mining in a background tab also comes to mind. Would it make sense for GPU access to be a permission that users have to explicitly grant?