• 0 Posts
  • 8 Comments
Joined 3 years ago
cake
Cake day: July 9th, 2023

help-circle



  • Any non-dummies out there willing to dummy this down for me?

    If I’m picking up what was being put down, websites typically reserve a small amount of space on a hard drive for any given website to install scripts they need to function. This is done as a matter of course, and is largely the modern Internet working as intended (for better or worse). However, in this case, a compromised website could instruct my browser to reserve a gig or more of space to deploy or install this FROST script. This reports back to the attacker what programs are competing for resources on my computer, including my individual browser tabs and what sites those tabs contain. It can do this despite the location where browsers let websites install/run scripts being nominally sandboxed away from the rest of the drive. It does this by measuring the latency of certain I/O operations occurring on the drive, and feeding that information through some sort of neural network.

    Assuming that is generally correct from a layman’s POV, how exactly is that latency information sufficient to determine what programs or websites I have open? Wouldn’t different models of SSD (or even different SSDs of the same type) have minor variations in performance which would make this impossible? Hell, how does the script even know that it is installed on an SSD and not an HDD?

    Not saying it untrue, because obviously the folks that discovered this know a touch more about computers than me, but, if this explanation were trotted out in a thriller movie (“well, President Ryan, we know the location of the terrorists’ hideout because we were able to measure the latency of their hard drive, which revealed they were placing an Amazon order in the other tab”), I’d chalk it up to techno-babble nonsense.



  • Hazarding a guess that they feel OP is using schizo as a shorthand reference for crazy/delusional, given the context is Internet conspiracy theories. They possibly feel that it is being used as a perjorative which disrespects folks who struggle with schizophrenia. In essence, calling something you find crazy “schizo” is the same as calling something you find dumb “retarded”.

    I don’t have a dog in the fight one way or the other, but, in the absence of their reply, that’s my assumption.



  • Sorry man, I’m not knowledgeable enough about computers to provide a summary, but I’ll mention this fun tidbit: apparently, the shipped version of task manager contained thus guy’s home phone number in the code by accident. He commented it out, but left the phone number in there, which means he can find instances of the source code being hosted online by reverse searching his home phone. Which is still a number he maintains, and he asks people not to call. Which is a bold thing to leave in the video imo