Live data from Hacker News

This JavaScript can snoop on other browser tabs to work out what you're visiting

theregister.co.uk

31–40 of 68 posts

Re: This JavaScript can snoop on other browser tabs to work out what you're visiting

#31

Disabling JavaScript completely will kill off the attack, but also kill off a lot of websites, which rely on JS functionality to work. All the more reason to not have JS on by default, and oppose the growing population of sites which unnecessarily use it. That's been my configuration for many years, and in my experience the vast majority of sites I visit do not require it; in fact, contrary to the frequent "please en…

I don't browse without the ability to toggle JS on or off by domain. JS isn't completely off, but sites generally work, but ads don't.

https://addons.mozilla.org/en-US/firefox/addon/umatrix/

https://chrome.google.com/webstore/detail/umatrix/ogfcmafjal...

or:

https://addons.mozilla.org/en-US/firefox/addon/noscript/

Re: This JavaScript can snoop on other browser tabs to work out what you're visiting

#32
post #19
post #3

I think it would be more appropriate to link the paper[1] and use its title (as it's much more descriptive). [1] https://arxiv.org/abs/1811.07153 Robust Website Fingerprinting Through the Cache Occupancy Channel

Leave it to The Register to clickbait the research. This is nothing new btw. Side-channel attacks on other tabs have been known for more than a decade, and is one of the legitimate reasons why the NoScript plugin was developed, among others.

They are not 'clickbaiting' it in the web-sense, they're just doing what they do with all stories:

They use UK tabloid newspaper style headings, have always used this style, and probably will always use this style. It's not clickbaiting, it's a parody on UK newspapers then with an informative article, usually with plenty of sarcasm.

I don't think The Register is looking for Google click-through revenue for people with a search phrase consisting 'cacheflow', 'javascript', and 'browser tabs'.

The article explicitly mentions

> Side-channel attacks on other tabs have been known

Yes, it mentions that, and

> one of the legitimate reasons why the NoScript plugin was developed

It didn't mention NoScript, indeed it didn't. But it did mention the general case

> Disabling JavaScript completely will kill off the attack,

Re: This JavaScript can snoop on other browser tabs to work out what you're visiting

#33

Disabling JavaScript completely will kill off the attack, but also kill off a lot of websites, which rely on JS functionality to work. All the more reason to not have JS on by default, and oppose the growing population of sites which unnecessarily use it. That's been my configuration for many years, and in my experience the vast majority of sites I visit do not require it; in fact, contrary to the frequent "please en…

Hah, I'm thinking of making a little banner that says something like

"Hi! It seems you have Javascript enabled by default. While on this site, Javascript enables [features], it's a good security practice to use [browser extensions] to enable it on a per-site basis.

Many malicious practices depend on Javascript, and can leave you open to damage to your things like leaking of personal information (including any site knowing what other browser tabs you have open), and combining that information with other information ad trackers have gathered on you to be used by who knows who for who knows what reasons. One thing is sure, it likely won't be anything you initiated or wanted.

For any site that requires you to expose yourself to harm to get content, you might be able find one that has the better content and respects you, if you look some more. If it's not made from 100% ethical craftsmanship, you deserve better! So check out our web ring; we're the good guys, and you're a bad person if you don't agree.

[web ring stuff]"

Well, roughly like that :P And yeah, I know it all falls down when the banner keeps showing up when a user enabled Javascript with an extension :(

Seriously though, I agree with you, and I think it's silly to be on the defensive. Bring back web mastery, at least as a niche, that people who want that can find, and where people give each other shit for sites not being "ethical" (for lack of a better shorthand) or backwards-compatible enough, too bloated, bad with screen-readers etc.. I would find that refreshing, actually. It technically never went away, the universe just expanded so quickly. There's still sites made like that, there's still good tutorials, but they're in the backseat of the huge "world of web dev", and could be be actually driving in their own niche. Confidence, maybe some principles and a way to affirm them, and users to find or recognize sites that affirm them, is really all that's needed.

I guess calling it "ethical" is not great branding, but surely people have already come up with (and maybe organized) what I mean, with a better phrase for it? If anything comes to mind, just shout it out please.

Re: This JavaScript can snoop on other browser tabs to work out what you're visiting

#34
>This fingerprinting attack involves using JavaScript to measure processor cache access latency over time as websites are loaded

Can someone explain to me how exactly can JavaScript measure processor cache access latency? Also, isn't the performance of inactive tab supposed to be throttled?

Re: This JavaScript can snoop on other browser tabs to work out what you're visiting

#35
post #19

Earlier quoted context omitted.

Leave it to The Register to clickbait the research. This is nothing new btw. Side-channel attacks on other tabs have been known for more than a decade, and is one of the legitimate reasons why the NoScript plugin was developed, among others.

It's not ‘clickbait’, it's a headline. It's meant to attract attention and engage the user. See the red top header The Register uses? That's a nod to British tabloid newspaper mastheads going back decades, and The Register likens itself to similar hovels of deplorable journalist talent-waste. Not everything is some clinically cynical attempt to con the contemporary reader — sometimes such effort is intentionally tong…

There's a point at which pretending to be a jerk becomes indistinguishable from actually being a jerk.

Re: This JavaScript can snoop on other browser tabs to work out what you're visiting

#36
> processor cache occupancy

Shoot, why not just browser cache occupancy? Is it possible to fingerprint the New York times as JavaScript and check to see if it's loaded out of the cache?

> Boffins

Ah the register... Always gives me a chuckle, especially the never ending beer 'curing' everything series

Re: This JavaScript can snoop on other browser tabs to work out what you're visiting

#37
post #3

I think it would be more appropriate to link the paper[1] and use its title (as it's much more descriptive). [1] https://arxiv.org/abs/1811.07153 Robust Website Fingerprinting Through the Cache Occupancy Channel

No. The Register's "clickbait" title is better and more descriptive.

I (and most other people?) have NO IDEA what the "Cache Occupancy Channel" is, nor is it clear from the title of original source article that this is about a technique that allows an attacker to potentially determine what websites the target is visiting on other tabs in target's browser.

Re: This JavaScript can snoop on other browser tabs to work out what you're visiting

#38
post #7

This sounds worrying. Shouldn't your browser prevent this from happening?

"we simply do not need high-resolution timers for the attack" Not sure there's a lot they could do, short of apis that actively tell lies or introduce deliberate random pauses.

That works for throwing Shai Hulud off the track.

Re: This JavaScript can snoop on other browser tabs to work out what you're visiting

#39
post #25

Disabling JavaScript completely will kill off the attack, but also kill off a lot of websites, which rely on JS functionality to work. All the more reason to not have JS on by default, and oppose the growing population of sites which unnecessarily use it. That's been my configuration for many years, and in my experience the vast majority of sites I visit do not require it; in fact, contrary to the frequent "please en…

I'm not sure what sites you're visiting but most sites i have attempted to use with JS disabled simply did not function and thought I was a robot. I was then presented with a human verification process that required javascript to run. But yes I can disable javascript on HN.

Yeah, screw those sites. I do toggle JS on for select places that I have more trust in, but generally most places I browse work fine.

There is no site so wonderful and special that I'll tailor my operating environment to suit their business model for the privilege of viewing it.

Re: This JavaScript can snoop on other browser tabs to work out what you're visiting

#40
I see a lot of suggestions to throttle or randomize the cache somehow, and none to stop JavaScript for background tabs. What are the reasons that disallowing background JS might not be preferable? Doesn’t Safari do this by default? And I’m not sure but I imagine that even allowing a background timeslice every once in a while would allow for background notifications and connections while preventing timing attacks?
Post reply on HN