Re: [compute-pressure] Feature can be abused to create cross-site covert channels (#197)

Hi all,

I read through the document. In general, I think it reads well but I think it would be great if we could add discussion on cross-site covert channels in more privacy-focused browsing experiences such as incognito (private) mode as well. What is your opinion on this?

Just to give some context on the reasons why I prompt this: 
We did a forensic analysis on private browsing a long time ago (all patched now, except for the resource allocation fingerprinting, a notion similar to a covert channel): 
[On the privacy of private browsing–a forensic approach](https://link.springer.com/chapter/10.1007/978-3-642-54568-9_25) -> open access link: https://eprints.ncl.ac.uk/file_store/production/197264/D8ACC693-D092-41D2-8682-1521007F31A6.pdf

Cheers,
Ehsan

-- 
GitHub Notification of comment by toreini
Please view or discuss this issue at https://github.com/w3c/compute-pressure/issues/197#issuecomment-1592785203 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Thursday, 15 June 2023 10:30:09 UTC