New side channel attack via CSS3 feature "mix-blend-mode"

Suggestions and feature requests for the Pale Moon browser

Moderator: satrow

LigH1L
Moon lover
Moon lover
Posts: 79
Joined: Fri, 22 Feb 2013, 19:08
Location: NoDSL.de - rural central Germany

New side channel attack via CSS3 feature "mix-blend-mode"

Unread postby LigH1L » Thu, 31 May 2018, 19:56

I only heard about a newly found security risk to spy on IFRAME content; Firefox and Chrome are known to be vulnerable.

Evonide Security Research: Side-channel attacking browsers through CSS3 features

Not to cause panic, just to have it mentioned. Maybe you can imagine a strategy in case your render engine is affected too.

The description sounds like it depends delicately on timings in transparency calculations.
Last edited by LigH1L on Thu, 31 May 2018, 19:59, edited 2 times in total.

User avatar
ketmar
Lunatic
Lunatic
Posts: 302
Joined: Tue, 28 Jul 2015, 11:10
Location: Earth

Re: New side channel attack via CSS3 feature "mix-blend-mode"

Unread postby ketmar » Fri, 01 Jun 2018, 11:40

no SmartName? no dedicated site? meh, that's not how it is done these days!

User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 21462
Joined: Sun, 28 Aug 2011, 17:27
Location: 58.5°N 15.5°E
Contact:

Re: New side channel attack via CSS3 feature "mix-blend-mode"

Unread postby Moonchild » Fri, 01 Jun 2018, 13:01

As far as I've seen, none of these pixel stealing attacks work on Pale Moon, and "just in case" some DiD measures were put in place months ago. Combine that with a cautious approach to performance timers and it's at most impractical, but more likely just never works.
Improving Mozilla code: You know you're on the right track with code changes when you spend the majority of your time deleting code.

"If you want to build a better world for yourself, you have to be willing to build one for everybody." -- Coyote Osborne

LigH1L
Moon lover
Moon lover
Posts: 79
Joined: Fri, 22 Feb 2013, 19:08
Location: NoDSL.de - rural central Germany

Re: New side channel attack via CSS3 feature "mix-blend-mode"

Unread postby LigH1L » Fri, 01 Jun 2018, 13:22

I hoped to hear that. Thank you. :thumbup:


Return to “Suggestions/feature requests”

Who is online

Users browsing this forum: No registered users and 2 guests