from the mozilla security blog:
> Our internal experiments confirm that it is possible to use similar techniques from Web content to read private information between different origins.
https://blog.mozilla.org/security/2018/01/03/mitigations-landing-new-class-timing-attack/