Hot Pixel' Attack Steals Data from Apple, Intel, Nvidia, and AMD Chips
tomshardware.com
tomshardware.com
Sounds like one of those attacks that works in theory but is too impractical to use in real life. This is harder than cache side channel attacks, and we still haven’t seen much use of those in the wild, years later.
> Ultimately, this furthers other attacks, like website fingerprinting.
Umm no. Did ChatGPT write that? Fingerprinting isn’t an attack and that’s not how it works. Also this requires access to system temperatures and other metrics that are absolutely not available from JavaScript.
No problem, just use a zero-day to get full system access and then you can read the temps and send them back to JavaScript.
It's unfortunate that this article is poor, but the paper itself is clear and readable.
What is actually used is enough (not large, not small, not one usually... just enough) items with some spread in statistics such that one gathers enough such things so they can conclude to some level of certainty the device is uniquely determined.
Thus any new piece of data that provides any amount of device discrimination is useful. This new method fits the bill. And it will open the door to much more advanced attacks, as all new attacks do.
Easier ways, i.e., more well known, are also more commonly spoofed, blocked, faked, or mitigated by all major intelligence agencies and large sections of industry. New methods are always welcome, and they too will eventually become less useful as mitigations and defenses are developed. It's an arms race, and you're happy to throw rocks at people in T-shirts when professionals have moved on to more sophisticated weapons and armor.
Feel free to address the content of the message once you have actual facts. To help you get some I'd recommend reading a few recent papers from https://scholar.google.com/scholar?hl=en&as_sdt=0%2C15&q=bro...
The Chrome developers at Google are preparing a WebHWiNFO proposal as we speak.
But when you read further and see what they tried:
We then selected one Arm instruction from each data-processing bucket,testingstores(str),AESinstructions(aese, aesmc), rotate right (ror), bitwise and (and), and both integer and floating-point addition (add, fadd) and multiplication (mul, fmul). We run each instruction in a loop on all available P-cores on each test device
What they did is define a handful of known workloads, with very different power profiles. And then they find that they can tell them apart by looking at the power of the chip. Well, duh.
Looks like only a local user can do this, but the article is not to clear on that.
Anyway this seems very hard to do. Also I wonder if using OpenBSD's port obsdfreqd can prevent this. Based upon usage, it will adjust the frequency and CPU Temp on the fly.
https://tildegit.org/solene/obsdfreqd
edit: grammer