Elektrine
EN
Log in Register
Paige Chat Timeline Gallery Friends Lists Email Drive DNS Resolver Domains VPN Kairo Nerve
Remote

Hannes Weissteiner

@hweissi@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

PhD Candidate at @isec_tugraz@infosec.exchange. Playing CTF with LosFuzzys

44 Followers
43 Following
8 Posts
Joined October 11, 2024
Website:
https://hannesweissteiner.com/
Open post
Hannes Weissteiner @hweissi@infosec.exchange
· 4mo ago

Announcing my latest first-author paper, accepted to #DIMVA2026:
❄️ FROST: Fingerprinting Remotely using OPFS-based SSD Timing.

While SSD contention-based side channels have been demonstrated from native code before, we bring them to the browser.

We use the Origin-Private File System (OPFS), which allows any website to use up to 10GB (Firefox), or 60% of total disk space (other browsers), from JavaScript, without any user interaction or special permissions.
We use a file larger than system RAM to measure SSD latencies, bypassing the page cache to guarantee disk access.
From the resulting traces, we can infer website visits (even across browsers!) and application startups.

While we did most of our evaluations on macOS, the underlying mechanisms are platform-agnostic.
This is a feature, not a bug!

Read the paper here: https://hannesweissteiner.com/publications/frost/

Thanks to Tobias Weiser, @wayna@infosec.exchange, @vmcall@infosec.exchange, Fabian Rauscher, Jonas Juffinger and @lavados@infosec.exchange for the collaboration!

8
2
11
1
Open post
Hannes Weissteiner @hweissi@infosec.exchange
· 7mo ago

I'm looking forward to presenting my paper, "Continuous User Behavior Monitoring using DNS Cache Timing Attacks" at NDSS next week!
We mount an Evict+Reload-style attack on the local DNS cache, detecting recently accessed domains and evicting to continuously monitor new accesses.

Our attack works from native code, even across virtual machines and containers.
We also run the attack in the browser from a malicious website, using JavaScript or even scriptless HTML+CSS.
Most underlying primitives are OS-agnostic!

Read the paper here: https://hannesweissteiner.com/publications/dmt/

Thanks to Roland Czerny, @silent_bits@infosec.exchange, @notbobbytables@infosec.exchange , Johanna Ullrich and @lavados@infosec.exchange for the amazing collaboration!

17
0
12
0
Open post
Hannes Weissteiner @hweissi@infosec.exchange
· 4mo ago
Replying to @hweissi@infosec.exchange
Update: seems like enough people complained that they reverted that decision: https://share.remarkable.com/l/3gFzgmf5J3QCuA Great, for now. I'm definitely keeping the old extension version archived though.
3
0
1
0
Open post
Hannes Weissteiner @hweissi@infosec.exchange
· 4mo ago
Replying to @hweissi@infosec.exchange
@mttaggart@infosec.exchange I looked a bit into it - apparently, Chrome does not require specific permissions beyond agreeing to install the extension, to inject content into the MAIN context of a page. So, it looks like all of the demonstrated things (stealing emails, exfiltrating repos, etc.) could be done with just a malicious extension, completely skipping the claude step. The only benefit it gives the attacker is that they can just tell claude what to do for them, instead of having to write (or vibecode) an actual exploit script. So, for the demonstrated exploits, the claude extension doesn't really seem to add any new capabilities beyond what an installed extension can do anyways.
0
2
0
0
Open post
Hannes Weissteiner @hweissi@infosec.exchange
· 4mo ago
Replying to @mttaggart@infosec.exchange
@mttaggart@infosec.exchange Wait, so any extension with zero permission can execute XSS code on any origin? Injecting prompts to claude is the least of my worries then. With that, can't the same extension just steal your github credentials?
0
3
0
0
Open post
Hannes Weissteiner @hweissi@infosec.exchange
· 4mo ago
Replying to @mttaggart@infosec.exchange
@mttaggart@infosec.exchange So does that mean you can essentially get local code execution by communicating with a locally-running claude instance? That would be a bigger issue. If it's only Claude in the browser, performing clicks for you - i don't think there's a lot of extra capabilities you get, compared to what you have already when you get someone to install the extension. After all, why communicate with a different browser extension, when you already have a browser extension running? However, still not great sandboxing by anthropic obviously.
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)
  • Source code

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 16:29:04 UTC