New Attack Can Track You Across Operating Systems Without Elevated Privileges
Researchers at the Graz University of Technology Austria demonstrated a new attack that can track you via file change events "on all systems," allowing for various data leaks.
Modern operating systems like Linux, Windows, and macOS provide built-in subsystems to monitor filesystem events: inotify, ReadDirectoryChangesW, and FSEvents. User processes can subscribe to receive file-operation notifications when actions like accessing, writing, opening, and closing are performed on a monitored file or directory.
While applications being able to see file change events seems rather innocuous, the researchers showed that it can actually leak a lot more than you'd think.
The attack assumes an attacker that has local, unprivileged access to a system and requires read access to a set of files in order to carry it out. But the set of files that are globally readable is "vast" and still leaks enough information to compromise sensitive data.
On Linux, they were able to achieve a keystroke timing attack, a type of side-channel attack that measures the timing between keypresses in order to infer information about the text being typed, including the actual text. This attack can leak passwords and any sensitive text being typed such as private messages.
They were also able to perform a fingerprinting attack on the top-100 websites since visiting certain websites would trigger specific access patterns for fonts in /usr/share/fonts/. From just this alone, an attacker can figure out what websites you're visiting.
In KDE specifically, they created a fake authentication pop up that could steal a user's password. Desktop environments implement focus-stealing protection that is meant to prevent attacks like this, but the KDE implementation is broken.
Android, also a Linux-based family of operating systems, fared better than desktop Linux, but still leaks the existence of files and filenames, which can be highly revealing in a private messenger such as WhatsApp.
In Windows, full paths of all files, including ones they didn't have permission to read, were accessible, an undocumented behavior.
On Windows they could monitor the website visits of all users in real time. There are no false positives, since they can directly measure it rather than relying on a side-channel.
On macOS, they were able to read connectivity settings such as Bluetooth activation or plugging/unplugging a network cable.
Installing, updating, and other application behavior were observable as well.
The researchers say they responsibly disclosed the attacks to the vendors. In particular, Microsoft stated that the the private data leakage was actually there by design.
Community Discussion