this post was submitted on 01 Jun 2026
45 points (95.9% liked)
technology
24384 readers
139 users here now
On the road to fully automated luxury gay space communism.
Spreading Linux propaganda since 2020
- Ways to run Microsoft/Adobe and more on Linux
- The Ultimate FOSS Guide For Android
- Great libre software on Windows
- Hey you, the lib still using Chrome. Read this post!
Rules:
- 1. Obviously abide by the sitewide code of conduct. Bigotry will be met with an immediate ban
- 2. This community is about technology. Offtopic is permitted as long as it is kept in the comment sections
- 3. Although this is not /c/libre, FOSS related posting is tolerated, and even welcome in the case of effort posts
- 4. We believe technology should be liberating. As such, avoid promoting proprietary and/or bourgeois technology
- 5. Explanatory posts to correct the potential mistakes a comrade made in a post of their own are allowed, as long as they remain respectful
- 6. No crypto (Bitcoin, NFT, etc.) speculation, unless it is purely informative and not too cringe
- 7. Absolutely no tech bro shit. If you have a good opinion of Silicon Valley billionaires please manifest yourself so we can ban you.
founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
The whole thing is client-side JavaScript. The attacker won't care about resources used, in this case, because the victim foots the bill
Does mean it'll be pretty easy to detect at least.
Though if I were using something like google maps I wouldn't notice an extra 1GB.
I just read the paper and it isn't 1GB, it's system ram. So it has to create a file in your OPFS that's closer to 32GB.
It can also only fingerprint the top 100 sites right now.
It will also noticably slow things down since it's clearing your page cache 1000 times/sec which means you're running almost entirely in swap/disk space.
Firefox is also the only one that limits OPFS size (10GB) so they need to create multiple files if you have more than 10GB or ram.
So it's basically a non-issue unless it becomes far more efficient?
Unless I'm reading it wrong? Seems like it's more of a "we can get your hardware to behave a certain way, even when sandboxed" thing than a "this is a very serious security vulnerability" thing?
I don't see how it could become more efficient since the attack vector is basically just filling your ram and forcing your OS to clear the page cache.