Your SSD Is Snitching: How FROST Turns Storage Timing into a Fingerprint
You cleared your cookies. You’re on a VPN. Yet that oddly specific ad still follows you around. Turns out your paranoia might be calibrated correctly. A new technique called FROST (Fingerprinting via Read/Write Operations Storage Timing) lets websites identify your device by clocking how fast your SSD responds to reads and writes. The fingerprint isn’t in your browser anymore. It’s baked into the silicon under your keyboard.
Why an SSD Becomes a Fingerprint
Two SSDs off the same assembly line aren’t identical. Cell wear, controller firmware quirks, cache occupancy, thermal history — every drive develops its own performance personality. The older your laptop, the more pronounced those differences get.
FROST measures the gap at microsecond resolution. Write a file, read it back, watch how long it takes, study the distribution of delays, note where the latency spikes. Together those signals form a profile that points to one specific device with uncomfortable precision.
Here’s the kicker: you can’t clear this fingerprint. Short of swapping the drive, the same machine produces the same timing signature across every site it visits. Incognito mode is irrelevant. The hardware itself is the cookie.
OPFS: The Convenience Tradeoff Nobody Read the Fine Print On
The attack runs through the Origin Private File System (OPFS) — a browser API now shipping in Chrome, Safari, and Firefox. OPFS lets web apps create a real filesystem on your disk, which is why Google Docs and Figma can chew through gigabytes of data without feeling like a 2012 webpage.
The problem is what made OPFS fast in the first place. IndexedDB and LocalStorage go through layers of browser abstraction that smooth out timing noise. OPFS strips those layers away so writes hit the disk more directly. Performance went up. So did the leakage of physical storage characteristics straight into JavaScript.
Can We Actually Fix This?
Researchers propose three mitigations. Inject deliberate jitter into OPFS operations to muddy the timing signal. Lower the precision of timing APIs to the millisecond range. Or gate OPFS behind explicit user permission, the way we already do for cameras and microphones.
None of these are clean wins. Adding jitter kills the native-grade performance that made OPFS worth shipping. Coarser timers break legitimate web games, video editors, and WASM workloads that rely on precise measurement. Permission prompts annoy users into clicking yes on everything. It’s the same security-versus-usability tug-of-war we saw with Spectre and Meltdown, when every browser ate a performance hit overnight.
The Ad Industry Is Already Salivating
What makes FROST genuinely dangerous is how quietly it works. The attack is completely passive. No permission dialog. No console warning. No visible artifact. Any ad network or tracker can drop it into a one-line script and start fingerprinting visitors across the entire web.
Think about what that voids. A decade of cookie banners. GDPR consent flows. Apple killing IDFA. Safari’s Intelligent Tracking Prevention. Every time the privacy side closes a door, the tracking side finds a window — and this one wasn’t on anyone’s threat model. Hacker News and the security corner of X lit up after a researcher walkthrough hit YouTube on May 30, and you can see why. The whack-a-mole keeps escalating.
The Real Lesson
FROST isn’t really about SSDs. It’s a symptom of a bigger pattern: the browser is becoming an operating system, and every new OS-level capability we grant it widens the surface area for side-channel leaks. We wanted Figma in a tab. We got a hardware fingerprint in the bargain.
Worth asking, the next time a web app feels miraculously fast, what exactly it had to touch to get there. Your SSD is talking right now. You just don’t know to whom.
Comments
Loading comments...