Live data from Hacker News

Pixnapping Attack

pixnapping.com

21–30 of 75 posts

Re: Pixnapping Attack

#21
You know it's serious because it's got a domain and a logo. Even security researchers gotta create engagement and develop their brand.

Re: Pixnapping Attack

#22

Earlier quoted context omitted.

The blur happens in the compositor. It doesn't happen in the secure windows. >A secure window should draw 100% as requested or not at all. Take for example "night mode" which adds an orange tint to everything. If secure windows don't get such an orange tint they will look out of place. Being able to do post processing effects on secure windows is desirable, so as I said there is a trade off here in figuring out what…

> Take for example "night mode" which adds an orange tint to everything. If secure windows don't get such an orange tint they will look out of place. Being able to do post processing effects on secure windows is desirable, so as I said there is a trade off here in figuring out what should be allowed. That seems well worth the trade to me.

These sort of restrictions also often interfere with accessibility and screen readers.

Either the screen reader is built into the OS as signed + trusted (and locks out competition in this space), or it's a pluggable interface, that opens an attack surface to read secure parts of the screen.

Re: Pixnapping Attack

#24

Modern devices are simply too complex to be completely secure. We have this tendency of adding more and more "features", more and more functionality 85% of which nobody asked for or has use for. I believe that there will be a market for a small, bare bones secure OS in the future. Akin to how freeBSD is being run.

Bunnie's Precursor? It sounds cool, but it's also expensive as fuck. If you thought $100 for a graphing calculator was a ripoff, the Precursor is a similar form factor and level of computational power, but costs $1000 and can't be used in maths exams.

https://www.bunniestudios.com/blog/2020/introducing-precurso... (currently down, might be up later)

Re: Pixnapping Attack

#25
post #10

Earlier quoted context omitted.

The attack needs you to be able to alter the blur of pixels in a secure window; this could be forbidden. A secure window should draw 100% as requested or not at all.

The blur happens in the compositor. It doesn't happen in the secure windows. >A secure window should draw 100% as requested or not at all. Take for example "night mode" which adds an orange tint to everything. If secure windows don't get such an orange tint they will look out of place. Being able to do post processing effects on secure windows is desirable, so as I said there is a trade off here in figuring out what…

Right but night mode is built into the OS so you can easily make an exception (same for things like toasts). Are there use cases where you need a) a secure window, and b) a semi-transparent app-controlled window on top of it?

Re: Pixnapping Attack

#27

Things like this make me wonder if the social media giants use attacks like these to gain certain info about you and advertise to you that way. Either that or Meta's ability to track/influence emotional state by behaviour is that good that they can advertise to me things I've only thought of and not uttered or even searched anywhere.

Are you sure that isn't just the horoscope effect?

Re: Pixnapping Attack

#28

Things like this make me wonder if the social media giants use attacks like these to gain certain info about you and advertise to you that way. Either that or Meta's ability to track/influence emotional state by behaviour is that good that they can advertise to me things I've only thought of and not uttered or even searched anywhere.

Similar people thinking similar thoughts I'd wager

Re: Pixnapping Attack

#29
post #26

My takeaway: Do not install apps. Use websites. Apps have way too much permissions, even when they have "no permissions".

The unfortunate truth is that so many things require a dedicated mobile app these days to use.

I don't own or carry a smart phone. I'm still able to get by without one, but just barely.

Re: Pixnapping Attack

#30

Things like this make me wonder if the social media giants use attacks like these to gain certain info about you and advertise to you that way. Either that or Meta's ability to track/influence emotional state by behaviour is that good that they can advertise to me things I've only thought of and not uttered or even searched anywhere.

Consider that your thoughts are a consequence of what you've consumed. They're not guessing what you think, they're influencing it.
Post reply on HN