HN Hall of Fame Weekly email

Stealing sensitive browser data with the W3C Ambient Light Sensor API (2017)

blog.lukaszolejnik.com Essays & writing Essays & articles Security & privacy Candidate
Screenshot of blog.lukaszolejnik.com captured 2026-07-20
Page preview · captured 2026-07-20

Resurfaced independently across 2 calendar years, with breakout response in 2 of them.

submissions
9
submitters
9
observed span
2017–2019
peak thread · 51 comments
113 pts
latest 20+ return · 2019-10-14
113 pts

Submission timeline

2007–2026

One slot for every year since HN launched. Height is that year's peak points; orange marks a 100+ point or 50+ comment breakout. Select a bar to open its strongest thread.

First comments on top threads

HN comment order

> There is currently an ongoing discussion within a W3C Device and Sensors Working Group whether to allow websites access the light sensor without requiring the user’s permission. Why is this even a thing? Just make this the same as location or microphone prompts? I never understood the fear of being transparent or give choice to users. I hope at least firefox has a setting to permanently disable this feature.

tyfon·113-point thread·

What was the purpose of exposing the Ambient Light Sensor to web pages in the first place? The W3C document[0] has a few suggestions: > A Web application provides input for a smart home system to control lighting. > A Web aplication checks whether light level at work space is sufficient. > A Web application calculates settings for a camera with manual controls (apperture, shutter speed, ISO). > A Web application monitors light level changes produced by hovering hand user…

The first top-level comment from each of the four biggest threads, in HN’s own order. Excerpts are shortened; open a comment for full context.

Breakout years
2

100+ points or 50+ comments

Total points
232

reference only — not used in Hall rules or ranking

Total comments
77

reference only — not used in Hall rules or ranking

Every submission