3 ms·
To be really dangerous, I think this would need to defeat client-side cache strategies. If the browser caches each resource, the server-side reads wouldn't acco
by tritium 9y ago
To be really dangerous, I think this would need to defeat client-side cache strategies. If the browser caches each resource, the server-side reads wouldn't account for repeated characters or overall length with perfect accuracy. Consider palindromes like "racecar."
This would still put many, if not most, passwords within guessable striking distance, for anyone able to intercept plain-text HTTP traffic, between Alice (the client) and Bob (the CSS image resource server).
- theandrewbailey 9y agoThis might need to defeat backspace, too.
- regularhackerer 9y agoKeylogger server response can recommend the browser not to cache.
- alasdair_ 9y agoThe server just returns a 400, causing the browser to no longer cache it.
- tritium 9y agoTrue! And now I’m realizing, depending on position in the network, the server doen’t even need to exist, if one only needed to MITM the request traffic... Geeze.