Open Bug 1852277 Opened 9 months ago Updated 8 months ago

Audit Web APIs for Hardware Acceleration

Categories

(Core :: Privacy: Anti-Tracking, defect)

defect

Tracking

()

People

(Reporter: tjr, Unassigned)

Details

(Keywords: privacy)

We are concerned that Web APIs that offer hardware acceleration (when the underlying hardware supports it) can be used to distinguish machines based on outlier computations/inconsistent evaluation of inputs.

I'm not super-concerned with this at the moment, until we know it's a problem. Typically difference in behavior is itself a bug (e.g. in WebCrypto) that needs to be fixed, so if we find evidence of it happening (and evidence that fingerprinters care about it) we really only need to act if we can't /won't fix the underlying difference.

The exception to this is the MediaCapabilities query in Bug 1436226 which is still outstanding I believe.

Component: General → Privacy: Anti-Tracking
Keywords: privacy
Product: Firefox → Core

What would be the priority and severity for this?

Flags: needinfo?(tom)
Severity: -- → S3
Flags: needinfo?(tom)
You need to log in before you can comment on or make changes to this bug.