w3c / w3c/webcodecs

Timing attack privacy consideration

Open
#234 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

editorial privacy-needs-resolution
Dominant language
HTML
Stars
1.3k
Forks
194
Avg merge
1d 13h
Merged PRs (30d)
3

Description

As discussed in the privacy review, timing attacks allow for profiling of the users machine.

As highlighted by @kdzwinel - This could be an increased exposure to other CPU profiling exposed via other methods as the codecs will allow for granular GPU hardware acceleration

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No file, test, or entry point is identified. Start by reviewing the referenced privacy review and the WebCodecs codec and hardware-acceleration behavior; the issue is done only when the project has an agreed mitigation or documented resolution for timing-based CPU and GPU profiling exposure.

Written by the indexing model from the issue text.

Assessment

Domain
audio-video-rtc, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.