Skip to content

Conversation

szager-chromium
Copy link
Collaborator

@szager-chromium szager-chromium commented Oct 13, 2020

Closes #403
Closes #404


Preview | Diff

which has privacy and security considerations of its own. It is however unlikely that
{{IntersectionObserver}} is vulnerable to timing-related exploits. Timestamps are generated
at most once per rendering update (see [[#event-loop]]), which is far too
infrequent for the familiar kind of timing attack.
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah, we're just exposing the same timestamp as requestAnimationFrame, so...

@szager-chromium szager-chromium merged commit 54d5de5 into master Oct 19, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

PING Review: High Resolution Time PING Review: No privacy considerations section

2 participants