Timing attack against HSTS to sniff browser history in Chrome and Firefox
zyan.scripts.mit.edu
Timing attack against HSTS to sniff browser history in Chrome and Firefox
1–10 of 99 posts
Re: Timing attack against HSTS to sniff browser history in Chrome and Firefox
#2Probably a good idea to edit the title to indicate that this is an example attack site as well, not my favorite thing in general to land on without warning.
No js seems to mean no worries though.
Re: Timing attack against HSTS to sniff browser history in Chrome and Firefox
#3[deleted]
Re: Timing attack against HSTS to sniff browser history in Chrome and Firefox
#4One nice thing is that it is quite inaccurate, I've visited a large number of the sites it tells me I haven't.
Re: Timing attack against HSTS to sniff browser history in Chrome and Firefox
#5Wow. Our corporate proxy isn't going to like that many requests that quickly from one box. I wonder if they can add a landing page.
Re: Timing attack against HSTS to sniff browser history in Chrome and Firefox
#6I hit the page from Chrome 45.0.2454.101 and it literally did not get a single site that I regularly visit. It did make a hit on Reddit, I guess, but I have only visited the site two or three times, and you could probably say that about 2/3 of the population.
Re: Timing attack against HSTS to sniff browser history in Chrome and Firefox
#7Wow. Our corporate proxy isn't going to like that many requests that quickly from one box. I wonder if they can add a landing page.
Yan has hit the HN homepage before, so hopefully it can weather this storm too.
Re: Timing attack against HSTS to sniff browser history in Chrome and Firefox
#8How much of this is accurate, and how much of this is simply the top XXX sites that people visit?
Re: Timing attack against HSTS to sniff browser history in Chrome and Firefox
#9How much of this is accurate, and how much of this is simply the top XXX sites that people visit?
[deleted]
Re: Timing attack against HSTS to sniff browser history in Chrome and Firefox
#10A slide discussing HSTS+CSP attack (this one) and also HPKP attack: https://zyan.scripts.mit.edu/presentations/toorcon2015.pdf