Front-End Performance: The Dark Side
dev.opera.com
dev.opera.com
First, the cache storage mechanism in service workers allows a site's javascript to cache a 3rd party request it has loaded through the fetch API. Caches aren't thinking about timing attacks, and in general are performance sensitive, so it's reasonable to expect that larger resources will take longer to cache and this time can be observed by the page.
Second, you can generate facebook posts which are targeted to specific demographics - like age ranges or specific ages. This will generate URLs which will have a different page length when loaded by logged in users in the target demographic compared to others. It looks like this is possible because there is not an explicit 'access-control-allow-origin' header set on facebook, and while the 'x-frame-options:deny' prevents loading of the content, it can still be cached by a 3rd party.
(I'm one of the researchers mentioned in the presentation.)
CORS has nothing to do with it, actually. This is where the strength of the attack lies.
Blacklists don't work in the Facebook model.
The reason facebook offers those filters is because a lot of posts are public yet facebook still offers a way to limit the audience.
Filtering the audience using circles is what Google+ did and proved to be unpopular.
I disagree that the failure of Google+ means that nobody wants privacy settings, or in general that the failure of a business means that every single minor innovation they made was flawed. Google+ failed because of the network effect - a social network is only useful if it's also used by people you want to socialize with.
People consistently list privacy controls as among their biggest problems with Facebook, and circles solved that problem neatly once people figured out how they worked. You can of course replicate a circle with a user list on Facebook, but it's nowhere near as obvious.
I was thinking maybe a hacker could actually judge age by the time that one or another reflex actions took someone. That would be a whole new level.
It’s a whole different story if you’re using server-side JavaScript (e.g. Node.js), though.