Researchers uncover privacy risks in long-standing file notification systems

← Back to the feed

Researchers uncover privacy risks in long-standing file notification systems

The Register · 49 minutes ago

Researchers at Graz University of Technology have identified long-standing weaknesses in file-notification systems used by Android, Linux, macOS and Windows. Although these systems do not expose file contents, their event data can reveal what users are doing, enabling attacks such as keystroke inference, website fingerprinting and credential theft.

The affected systems include Linux inotify, Android FileObserver, Windows ReadDirectoryChangesW and macOS FSEvents, some dating back more than two decades. Tests reportedly achieved 93.1–100% keystroke accuracy on Linux, 100% accuracy for remote SSH input and 87.9% accuracy when identifying visits to the top 100 websites; Linux has received only a partial fix, while no Android mitigation was reported. macOS exposed less information, but still revealed various system and application changes, while Windows could disclose file paths across users regardless of permissions.

  • File-event data can expose users’ activity without revealing file contents.
  • Attacks include keystroke recovery, website tracking and credential theft.
  • Linux is only partly fixed, with Android reportedly still unmitigated.

Business Gadgets Markets Research Science Technology

Read the full article at the source →

Originally published by The Register as “Decades-old file security flaws found in Android, Linux, macOS, and Windows”.