Security/privacy concerns beyond fingerprinting -- data exfiltration #182
Labels
privacy-tracker
Group bringing to attention of Privacy, or tracked by the Privacy Group but not needing response.
security-tracker
Group bringing to attention of security, or tracked by the security Group but not needing response.
Milestone
While the privacy considerations mention device and user fingerprinting, there are also more specific data exfiltration concerns. Among them:
By manipulating the device's state or screen state and then reading that, a malicious script could cause the exfiltration of data. https://blog.lukaszolejnik.com/stealing-sensitive-browser-data-with-the-w3c-ambient-light-sensor-api/
By sensing motion (possibly triggered by an alert in another window), a malicious script could learn user inputs, such as PINs. https://blogs.ncl.ac.uk/security/author/b2031864/
The text was updated successfully, but these errors were encountered: