3 ms·
The article describes that certain privacy extensions break the page from loading. It was probably ghostery. Honestly though the blank page fix seems horrible.
by justacomme555 8y ago
The article describes that certain privacy extensions break the page from loading. It was probably ghostery.
Honestly though the blank page fix seems horrible... especially when you consider twitter has worked very hard for the “above the fold” load times, at one point rendering it server side.
I also wonder if the attacker just pops a new window ( after getting the user to click anywhere) and load the twitter page into it, if they can still time the request the same way.
- justacomme555 8y agoI feel one better fix is to just add a small random wait from the time </html> is served and the TCP socket is actually closed. I donnt think? this should impact loads of the page when it is rendered in an html context.
- yorwba 8y agoThe delay should not be simply random, it would need to be carefully chosen to make the load time distribution independent of the user loading the page. Otherwise an attacker could just average multiple requests to get rid of the randomness.
- justacomme555 8y agoYoure right... the delay would basically have to be chosen dynamically to enforce a universal page load time for all html documents on twitter.com Still feels nicer than forcing a roundtrip
- eridius 8y agoThe article says certain extensions block the referrer, thus producing the manual link to click. I don't believe Safari Extensions can muck with the referrer that way, in terms of affecting resource loads I think it's limited to allow/deny. And besides, Twitter never showed me a manual link, it was just a completely blank page.