3 ms·
The potential problem I see with this is that it could be abused for a "have you loaded this resource" privacy leak. Simply pick a unique script on a website, i
by problems 10y ago
The potential problem I see with this is that it could be abused for a "have you loaded this resource" privacy leak. Simply pick a unique script on a website, if my server doesn't get a hit then I know you went there before.
- cryptarch 10y agoSave the load time and simulate it?
- cryptarch 9y agoWhy do you think this would be a bad idea?
- zrm 10y agoPossible solution is to have a content hash proxy trusted by the user but shared between multiple users. Then the site can only get the data at the proxy-level rather than the user-level, and not even that if the proxy is large enough to justify crawling the web to pre-cache everything, or is behind a larger cache that does.
- nothrabannosir 10y agoThat's not a solution but a work-around. The original privacy issue stands. browsers can't cache hashed content by default. :/
- zrm 9y agoThe browser would know if it had a content hash proxy configured and then could use it for all content hashed data. The issue becomes getting people to use one, but partial uptake is better than nothing. You could at least get most corporate and education environments with some equivalent to WPAD[1], and maybe even some consumer-level ISPs the same way if they want to reduce the traffic over their network. [1] https://en.wikipedia.org/wiki/Web_Proxy_Auto-Discovery_Protocol https://en.wikipedia.org/wiki/Web_Proxy_Auto-Discovery_Proto...
- 3pt14159 9y agoWe already have that though. Images and HSTS headers.
- homakov 9y agoWho cares someone went to X website? Even https is not protecting from that.
- staticassertion 9y agoIf I visit website A it should not know that I also visited website B. HTTP or HTTPS is irrelevant - they are totally separate connections and this does not assume anyone is in the middle. Of course, there are attacks that already work using cache timing, but that isn't a good thing.
- homakov 9y agoI know a handful of attack that work, and a few more vectors that won't be fixed as well. So why bother, exactly? It's neither a big concern nor fixable in current web design.