[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Public WebGL] CORS and resource provider awareness

The timing restriction patch that I intended to refer to was Adobe's
contribution to the ANGLE project (http://cs.chromium.org , search for
SH_TIMING_RESTRICTIONS) which prevents control flow decisions from
being made based on values fetched from textures. I believe that this
would defend against the side-channel timing attack which forced the
WebGL spec to disallow the use of cross-origin media.
Woah? Really? That sounds pretty intrusive.

Jeff Russell
Engineer, Marmoset