3 ms·
Does this mean you would have to visit a malicious website, that malicious website would open a different website with window.open(), and from this they can rea
by fh9302 3y ago
Does this mean you would have to visit a malicious website, that malicious website would open a different website with window.open(), and from this they can read data through this side channel attack?
- jeroenhd 3y agoThat seems to be the implication of this attack. The mitigation referenced by the web page are being rolled out in newer versions of Safari and iOS, according to other comments in these threads. The mitigation seems to be to split the process space. From the paper: Attacking Gmail. With Google being one of the world’s largest email providers, it is highly likely for a target to be signed in with their personal account. By having the event listener inside the attacker’s page access execute window.open(gmail.com), we can consolidate the target’s inbox view into the attacker’s address space. We then leak the contents of the target’s inbox, see Figure 11. Recovering Android Text Messages. Android users can send and receive text messages from a browser window by pairing their phone with Google’s Messages platform. Thus, by opening Google Messages using window.open(), we can recover a target’s text messages without attacking their mobile phone itself.
- paulirish 3y agoYes. But it's incredibly hard to pull off. My understanding is that the theory of this attack was introduced with Spectre. iLeakage adds enough research to create a working proof-of-concept, plus acknowledgment that, as of last year, it wasn't addressed in Safari. More on site isolation (the functionality that mitigates these attacks): https://w3c.github.io/webappsec-post-spectre-webdev/ https://w3c.github.io/webappsec-post-spectre-webdev/ https://www.chromium.org/Home/chromium-security/site-isolation/ https://www.chromium.org/Home/chromium-security/site-isolati... https://blog.chromium.org/2021/03/mitigating-side-channel-attacks.html https://blog.chromium.org/2021/03/mitigating-side-channel-at...
- mccr8 3y agoThere have long been working Spectre attacks. From skimming the paper a bit, I think the contribution of this work is that they have come up with an attack that works on Apple's processors, as well as bypasses for a number of mitigations WebKit has (that fall short of site isolation).
- jefozabuss 3y agoI think it's not that hard to pull this off as you can disguise this with a "social login" feature. E.g. imagine a website promoting raffles / free prizes if you log in with fb/insta/etc, there are way too many gullible users who'd use these pages. I'd not be surprised if accounts used in troll farms /bots/ are stolen this way.