3 ms·
Good points, but mostly just confusion on the specification, I think. > - the original server will not see your download request. This will skew their logs/sta
by gregable 8y ago
Good points, but mostly just confusion on the specification, I think.
> - the original server will not see your download request. This will skew their logs/statistics.
True in the strictest case if that site owner is strictly using http request logs for stats. The site owner must opt-in to this by signing their http exchanges, so this isn't something that will accidentally break someone unknowingly. Site owners have lots of ways of fixing this. More and more these days, logs are being recorded by javascript events anyway.
Note that this is also true of simple browser caching and prefetching. Caching preventing a request and prefetching adding a new one. This is why using server logs to understand audience behavior has limitations.
Also, this is one of the purposes of signed exchanges. In order to prefetch without violating the user's privacy, it's necessary to hide the download request from the origin server until after the user has clicked.
> - someone else will see what you are downloading instead. It's a privacy issue.
The originating server already has numerous ways of knowing all of this. Click tracking redirects, onclick event calls, etc can all register the user's click event off-site. Nearly all analytics tools already do this. The out-linking website owner also already can know the content of the page you will load as they can fetch it themselves. They will have done so in order to serve it as a signed exchange.
> It looks as if Signed HTTP Exchanges are opt-in at the moment.
In order to verify that the content is signed, a publisher must sign it using a private key. There really is no mechanism for this not to be opt-in in the future. The Signed Exchange format differs significantly from TLS connections (https) and there is no path to using the TLS connection to craft a signed exchange. The signed exchange spec in fact goes out of it's way to define a new certificate extension that is mutually exclusive with TLS certificates, so that a site owner must opt-in by way of getting a separate certificate issued.