5 ms·
I think you're forgetting that resources cannot be shared if they're marked private. You cannot get account_statement.js from your shared cache, it has to be un
by neverfone 8y ago
I think you're forgetting that resources cannot be shared if they're marked private. You cannot get account_statement.js from your shared cache, it has to be unique to you.
There is no easy fix to this.
- tripzilch 8y agoBut, if the server sends you a private resource, this implies the server must already know your identity. Being private it's not supposed to send it to anyone else, so it needs to identify you in order to know "does this user have access to this resource?". Am I missing something here?
- neverfone 8y agoYes, private doesn't necessarily mean authenticated, it just means shouldn't be saved in a shared cache. For example, "weather_at_your_geoip.js".
- jhasse 8y agoThe script tag could have a mandatory file hash attribute.
- yayana 8y agoYour example actually isn't incorrectly marked private.. So that is already covered in my previous comment. The most anonymity concious would realize they are trying to do banking in what is supposed to be their anonymous session and never fetch the file.. if they somehow missed that they were entering auth details? The way things need to work on the web involve choices that you apply differently (or IE applies for Windows users.) The defeatist response is not to implement any choices. A typical user will want a small number of PII sites, so let's have only PII mode and autofill their details into forms in any blog!
- neverfone 8y agoI'm not following your argument, do you agree that there are resources that cannot be saved in a shared cache?
- yayana 8y agoThere are resources that shouldn't be saved in a shared cache and shouldn't be seen in an anonymous session. It is not a coincidence that they are both and it is great that they are explicitly marked.