By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Online Tech Guru
  • News
  • PC/Windows
  • Mobile
  • Apps
  • Gadgets
  • More
    • Gaming
    • Accessories
    • Editor’s Choice
    • Press Release
Reading: Websites Can Now Spy on You Through Your Hard Drive
Best Deal
Font ResizerAa
Online Tech GuruOnline Tech Guru
  • News
  • Mobile
  • PC/Windows
  • Gaming
  • Apps
  • Gadgets
  • Accessories
Search
  • News
  • PC/Windows
  • Mobile
  • Apps
  • Gadgets
  • More
    • Gaming
    • Accessories
    • Editor’s Choice
    • Press Release
Anthropic Confidentially Files for What Could Be the Largest IPO Ever

Anthropic Confidentially Files for What Could Be the Largest IPO Ever

News Room News Room 1 June 2026
FacebookLike
InstagramFollow
YoutubeSubscribe
TiktokFollow
  • Subscribe
  • Privacy Policy
  • Contact
  • Terms of Use
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
Online Tech Guru > News > Websites Can Now Spy on You Through Your Hard Drive
News

Websites Can Now Spy on You Through Your Hard Drive

News Room
Last updated: 1 June 2026 16:08
By News Room 5 Min Read
Share
Websites Can Now Spy on You Through Your Hard Drive
SHARE

Over the decades, there has been no shortage of sites using clever techniques to covertly track visitors’ browsing histories, device fingerprints, and keystrokes and mouse movements in real time. Even Meta and Yandex were recently caught joining in the privacy-invasive free-for-all.

Now sites have a new way to spy on their visitors: by measuring subtle interactions with their solid-state drives. The technique, named FROST (fingerprinting remotely using OPFS-based SSD timing), allows sites to monitor other sites a visitor is viewing and what apps are open on their devices.

The technique, laid out in a research paper, exploits a side channel, a form of leak resulting from physical manifestations such as electromagnetic emanations, data caches, or the time required to complete a task. By measuring the manifestations, attackers can decrypt encrypted traffic and infer other confidential data.

The attack that FROST uses is known as a contention side channel, which measures the interaction of various processes all using (or competing for) a given resource. By measuring the timing of certain I/O (input-output) operations of the SSD a visitor is using, the researchers were able to determine the websites open in other tabs—even on other browsers—and the apps that were open on the visitor’s device. FROST requires no interaction from the visitor other than opening the site hosting the attack.

“Web browsers have evolved from simple document viewers into complex platforms capable of running sophisticated applications,” the paper authors wrote. “Companies like Google, Microsoft, and Adobe have developed full-fledged office suites, photo- and video editors, or even integrated development environments (IDEs) that run entirely within the browser.” The authors went on to note: “While these features enhance the capabilities of web applications and allow completely novel use cases, they also increase the browser’s attack surface, and some have already been shown to introduce new vulnerabilities.”

Unlike previous contention side-channel attacks on SSDs, FROST runs exclusively in the browser. It uses JavaScript that interacts with the OPFS (origin private file system), an allocated storage space that’s reserved for a specific site to run code needed to complete a given task. Websites can create one with no interaction required by the visitor.

While each file system is sandboxed, meaning it’s isolated from other websites and from the device system itself, the JavaScript can measure the I/O interactions. Then, by running those interactions through a pretrained convolutional neural network—a system that uses deep learning to analyze text, audio, and images—the attacker can deduce various apps and websites open on the device.

“The attacker continuously measures SSD contention by performing random reads from a large OPFS file,” the researchers explained. “SSD contention caused by user activity causes measurable latency differences for these read operations. By training a convolutional neural network (CNN) on these traces, the attacker can fingerprint user activity on the host system by classifying new traces using the trained model.”

The technique has its limitations. First, the OPFS file must be extremely large—likely a gigabyte or more. That requirement means that attacks at scale would inevitably be detected by many users. Additionally, the OPFS file must be stored on the same SSD the visitor is using. This isn’t usually a problem for tracking open websites, since the OPFS file is stored in the browser’s default location. In the event apps are using a separate SSD drive for apps, those apps couldn’t be detected by FROST.

One of the best ways to prevent FROST attacks is to close tabs as soon as they’re no longer needed. More savvy users can monitor the creation and size of OPFS files allocated by unknown websites. The researchers proposed ways for browser makers to shut down the side channel. One such method is to limit the maximum size of such files that are allowed. There are no indications FROST attacks have been performed in the wild.

Share This Article
Facebook Twitter Copy Link
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Pokémon TCG’s 30th Anniversary Set Features All Foil Cards and 30 New Pikachu

Pokémon TCG’s 30th Anniversary Set Features All Foil Cards and 30 New Pikachu

News Room News Room 1 June 2026
FacebookLike
InstagramFollow
YoutubeSubscribe
TiktokFollow

Trending

Computex 2026: All the news and announcements

Nvidia has officially entered the world of consumer laptop chips with the RTX Spark, and…

1 June 2026

Microsoft to unveil new AI models and Windows improvements at Build

Microsoft is heading to San Francisco this week in a bid to win back developers…

1 June 2026

“These sports games that were loved and revered… just went away” – How a group of ex-EA devs are launching a new NBA game

Back on July 23, 2024, indie studio Play By Play, formed by veterans of Electronic…

1 June 2026
News

Strava blames zero-code AI apps and scrapers as it tightens API access

Strava blames zero-code AI apps and scrapers as it tightens API access

In an update on its developer hub, Strava blames the change on “zero-code AI tools” that allow users to quickly create apps that “hammer” APIs. “We have felt this firsthand…

News Room 1 June 2026

Your may also like!

Video Games Could Have Movie-Style Product Placement to Counter Rising Costs, Ex-Dragon Age Boss Says
Gaming

Video Games Could Have Movie-Style Product Placement to Counter Rising Costs, Ex-Dragon Age Boss Says

News Room 1 June 2026
‘Sexual Chocolate’ Faces Recalls After FDA Tests Reveal Undisclosed Viagra
News

‘Sexual Chocolate’ Faces Recalls After FDA Tests Reveal Undisclosed Viagra

News Room 1 June 2026
Microsoft could be the next Big Tech antitrust target
News

Microsoft could be the next Big Tech antitrust target

News Room 1 June 2026
Best Sleep Trackers of 2026: Oura, Whoop, and Eight Sleep
News

Best Sleep Trackers of 2026: Oura, Whoop, and Eight Sleep

News Room 1 June 2026

Our website stores cookies on your computer. They allow us to remember you and help personalize your experience with our site.

Read our privacy policy for more information.

Quick Links

  • Subscribe
  • Privacy Policy
  • Contact
  • Terms of Use
Advertise with us

Socials

Follow US
Welcome Back!

Sign in to your account

Lost your password?