3 ms·
maybe not with CDNJS, but perhaps you don't want every website to know you have AshleyMadison.com assets cached.
by kami8845 6y ago
maybe not with CDNJS, but perhaps you don't want every website to know you have AshleyMadison.com assets cached.
- Uehreka 6y agoCan websites even tell what is cached and what’s pulled fresh?
- EE84M3i 6y agoYes, using timing
- amelius 6y agoNot if the javascript starts running only after all resources have loaded.
- darepublic 6y agoNo there could still be timing attacks after. Just dynamically request a cross domain asset
- amelius 6y agoThen those requests should not be cached?
- deleted 6y ago[deleted]
- tylerhou 6y agoconst start = window.performance.now(); const t = await fetch("https://example.com/asset_that_may_be_cached.jpg"); const end = window.performance.now(); if (end - start < 10/*ms*/) { console.log("cached"); } else { console.log("not cached"); }
- amelius 6y agoIn that case, the browser would always load the asset (it is not cached). So the rule would be that only stuff that is directly in the <head> may be cached (or stuff that is on the same domain).
- tylerhou 6y agoTo be clear, the context of the thread is "why do we need to partition the HTTP cache per domain." My example code works under the (soon-to-be-false) assumption that the cache is NOT partitioned (i.e. there is a global HTTP cache). > In that case, the browser would always load the asset (it is not cached). Agreed, if the cache is partitioned per domain AND the current domain has not requested the resource on a prior load. If the cache is global, then the asset will be loaded from cache if it is present: https://developer.mozilla.org/en-US/docs/Web/API/Request/cache https://developer.mozilla.org/en-US/docs/Web/API/Request/cac... > So the rule would be that only stuff that is directly in the <head> may be cached (or stuff that is on the same domain). You could be more precise here: with a domain-partitioned cache, all resources regardless of domain loaded by any previous request on the same domain could be cached. So if I load HN twice and HN uses https://example.com/image.jpg https://example.com/image.jpg on both pages, then the second request will use the cached asset.
- amelius 6y ago> To be clear, the context of the thread is "why do we need to partition the HTTP cache per domain." Ah right, the thread is becoming long :) > So if I load HN twice and HN uses https://example.com/image.jpg https://example.com/image.jpg on both pages, then the second request will use the cached asset. Good point!
- evilduck 6y agoWouldn't the act of timing a download mean that I download and pollute my cache with new assets from the site trying find where else I've been? Does this only work for the first site that tries to fingerprint a browser in this way?
- curryst 6y agoIs there a noCache option? Or can JS remove entries from the cache to reset it? Someone below mentioned doing requests for a large image that requires authentication. Short response time means the user isn't logged in (they got a 403), long response time means they downloaded the image and are logged in.