Hacker Newsnew | past | comments | ask | show | jobs | submit | dloy's commentslogin

If I google for kids show in Durban, even if not from Durban, I want to see Durban related results.


And they can’t with iPhones?


iOS doesn't let apps silently screen record.


That's not what's happening here. The attack is exploiting a side channel of the rendering behavior, not reading the screen. There's no particular reason to believe that iOS is immune to something like this, though certainly no claim has been made. It's a new idea, it'll take a while for people to puzzle through the implications.


How are you sure? This isn't abusing some poorly secured screenshot API, this is a timing attack on the GPU rendering process and impacts a wide range of GPUs.


No. This isn't Spectre/Meltdown for GPUs, it takes advantage of SurfaceFlinger giving apps information on what's drawn behind them.


This attack measures the time needed to draw each pixel which varies due to graphical data compression. It is based on the "GPU.zip" vulnerability which was shown to affect most modern GPUs, including from Apple.


Neither does Android. This is a timing attack on rendering.


You can't put one app on top of another, so that mitigates at least the 1st stage of this kind of attack.


Perhaps, or perhaps not. Maybe if we held them accountable they would?


Are we going to debate him on his argument or only on his character? Shoot the messenger I guess.


I would like to see the argument, too.


What character?


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: