3 ms·
These same guys had previously used WebGL to suck out text in the same way; unfortunately the demo is no longer at the same URL, but it is what's responsible fo
by randallu 13y ago
These same guys had previously used WebGL to suck out text in the same way; unfortunately the demo is no longer at the same URL, but it is what's responsible for the fairly weird implementation of CSS Shaders: http://www.schemehostport.com/2011/12/timing-attacks-on-css-shaders.html http://www.schemehostport.com/2011/12/timing-attacks-on-css-...
It's amazing that the same thing can be observed with the standard SVG software filters, though. I'd imagine that using X-Frame-Deny as they suggest is a much better solution than killing all JS (because you just know some incompetent ad network will manage to flip the switch and break millions of pages with that ability...).
- jffry 13y agoWould X-Frame-Options:DENY work to mitigate the view-source: attack?
- jffry 13y agoJust threw together a test case. X-Frame-Options does seem to mitigate the view-source attack: http://jsfiddle.net/GEynT/2/embedded/result/ http://jsfiddle.net/GEynT/2/embedded/result/
- joshfraser 13y agoTo be clear, the hack is still possible without view-source. It just makes it easier and more generic of a solution.