HOLogram's Input Vault aims to block keystroke timing data before page scripts can read it
HOLogram, an open protocol project, has detailed the design of its Input Vault module in the third installment of its development series. The module is built to intercept keyboard events at the earliest possible point in the browser, stripping high-resolution timing data that could be used to fingerprint users through keystroke dynamics analysis. Synthetic events are then re-emitted with accurate key identity and modifier states intact, so web pages continue to function normally. The implementation faces unresolved challenges, including identifying the optimal interception layer across Chrome, Firefox, and Safari, and handling IME composition events used for non-Latin script input. The team has opened research task R-01 to survey browser extension APIs and is inviting contributions from developers with relevant experience.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in