Hot Pixels: Frequency, Power, and Temperature Attacks on GPUs and Arm SoCs
arxiv.org
arxiv.org
General purpose computing is dead. The only way to reasonably assure lack of self-foot-shooting by end users is a mandatory signed code path from power on right down to application level software.
I'd say Raspberry Pi is an alternative, but the Raspberry Pi Foundation is committing an epic, Commodore-style self-own right now and the future of that platform is in jeopardy. Orange Pi and the like are nonstarters.
How much it will grow beyond 1%? Not much, if at all.
Not to diminish the work, it's an excellent lab experiment, but this has practically zero real-world application.
Can browser vendors just stop honoring the a:visited style completely? Or at least in iframes and other sources that don't arrive with the original page? That could initially be a configuration flag, like it was with rejecting third-party cookies.
I don't think that the impact of never coloring visited links differently would be noticeable for 99.99% users.
maybe better would be to limit styling just to color and when programmatically checked return value that should be when this class would be not present
This exploit avoids lookig directly at pixels, because the pixels are not available. It runs an SVG filter on these pixels, without looking at the result of filtering; it just measures how much time / energy did it take to render.
There should be no styling based on the browser history, shared across pages, or such history will be exfiltrated.