Websites can now spy on visitors by watching tiny timing changes in their SSDs.
According to Ars Technica, tor years, dodgy sites have used browsing histories, device fingerprints, keystrokes and mouse movements to stalk users in real time. Meta and Yandex were recently caught joining the same privacy-invasive war.
Now sites have a new trick called FROST, short for fingerprinting remotely using OPFS-based SSD timing. The technique lets a site infer other websites a visitor is viewing and which apps are open on their device.
FROST works by measuring subtle interactions with a visitor’s solid-state drive, which is a grimly clever way to turn storage into a snitch. The attack is described in a research paper and uses a side channel. That means it reads leaks from physical effects rather than breaking into the target directly.
Side channels can use electromagnetic emissions, data caches or the time required to complete a task to infer private information. FROST uses a contention side channel, which measures how different processes compete for the same resource.
By timing certain SSD input-output operations, researchers could identify websites open in other tabs and even in other browsers. They could also detect apps running on the visitor’s device. The victim only has to open the site hosting the attack.
The report said: “Web browsers have evolved from simple document viewers into complex platforms capable of running sophisticated applications. “Companies like Google, Microsoft, and Adobe have developed full-fledged office suites, photo- and video editors, or even integrated development environments (IDEs) that run entirely within the browser.”
The authors added: “While these features enhance the capabilities of web applications and allow completely novel use cases, they also increase the browser’s attack surface, and some have already been shown to introduce new vulnerabilities.”
Unlike earlier SSD contention side-channel attacks, FROST runs entirely in the browser using JavaScript that talks to OPFS, or origin private file system, a storage space set aside for a website.
Websites can create an OPFS without asking the visitor. Each file system is sandboxed from other sites and the operating system, but the JavaScript can still measure SSD input-output behaviour. The attackers then feed those traces into a pretrained convolutional neural network, a deep-learning system usually thrown at text, audio and images.
That lets them infer which websites and apps are open on the machine.
The report said: “The attacker continuously measures SSD contention by performing random reads from a large OPFS file. SSD contention caused by user activity causes measurable latency differences for these read operations. By training a convolutional neural network (CNN) on these traces, the attacker can fingerprint user activity on the host system by classifying new traces using the trained model.”
There are limits, which is fortunate because this one is creepy enough already. The OPFS file must be huge, probably a gigabyte or more. At scale, that sort of storage grab would be spotted by plenty of users.
The OPFS file must reside on the same SSD as the visitor’s. That is usually true for tracking open websites because browsers keep OPFS files in their default location. If apps live on a separate SSD, FROST cannot see them.
One practical defence is to close tabs when they are no longer needed, which will disappoint the 174-tab productivity cult. More technical users can monitor OPFS files created by unknown websites and watch for suspiciously large allocations.
The researchers suggested browser makers could reduce the risk by limiting the maximum size of OPFS files. There is no sign that FROST has been used in the wild.
The researchers ran the full FROST attack on an M2 Mac. On Linux, they showed that the underlying SSD latency measurement primitive works, but did not run the full attack. They didn’t try it on Windows.







