< antti > dropped a link
Some Questions and Answers
https://inoti.fyi/File-notification APIs on Linux, Android, Windows, and macOS leak user behavior because they report file events even when the attacker lacks read permissions for the files themselves. Accepted at CCS 2026, the research from Graz University of Technology demonstrates that an unprivileged local process can reconstruct keystroke timing via inotify on /dev/input, bypass Android’s FUSE storage isolation to track WhatsApp media transfers with file names, and monitor Windows filesystem events system-wide by watching the root directory. The Windows finding is particularly stark: monitoring C:\ reveals the full path of every touched file across users, allowing an attacker to identify visited websites with 97.8% accuracy for top-1000 sites via browser cache directories. Microsoft has labeled this behavior an "undocumented feature" and offers a registry policy to fix it, but that policy is disabled by default, leaving the vulnerability exploitable out-of-the-box.
The Linux issue received a partial kernel mitigation in early 2026 (CVE-2025-68788) by suppressing access events on character devices, which addresses the most severe /dev/input keystroke leakage but leaves other notification vectors intact. On Android, no fix is provided, and the attack remains fully functional against private app folders. The paper correctly notes that file contents are never leaked, only metadata such as names and timestamps, but argues this is sufficient for high-precision side-channel attacks when combined with existing timing analysis research. The work stands on solid empirical evidence rather than theoretical speculation, effectively exposing a systemic design flaw in how major operating systems handle filesystem observation permissions relative to data access controls.
what others said
- Hacker News 8 points · 1 comments
- Lobsters 37 points · 9 comments