39
you are viewing a single comment's thread
view the rest of the comments
[-] 01189998819991197253@infosec.pub 9 points 2 months ago

The researchers responsibly disclosed FROST to Google, Apple, and Mozilla before publishing. The responses are worth reading carefully:

  • Google said it does not consider browser fingerprinting to be a security vulnerability.

  • Apple described the attack as “currently out of scope,” with possible mitigations in the future.

  • Mozilla acknowledged the findings but has not implemented any fix.

In other words, the three companies that ship some of the world’s most-used browsers have collectively said “ok, not my concern”.

This isn't entirely true. Apple and Google said "piss off", but Firefox acknowledged the issue, but don't yet have a solution, which doesn't mean they aren't working on one. It is bad, though, that they haven't come up with something during the responsible disclosure timeline.

this post was submitted on 11 Jun 2026
39 points (100.0% liked)

Privacy

5082 readers
202 users here now

Icon base by Lorc under CC BY 3.0 with modifications to add a gradient

founded 3 years ago
MODERATORS