3 ms·
The script wouldn't have to be from a CDN to track people using the browser cache. I could infer whether you've visited a site that doesn't use CDNs or trackers
by daveFNbuck 6y ago
The script wouldn't have to be from a CDN to track people using the browser cache. I could infer whether you've visited a site that doesn't use CDNs or trackers by asking you to load something from that site and inferring whether you have that resource cached by the time it took you to load it.
- mmcwilliams 6y agoThis is true, but if you're running a CDN you have access to cross-domain user information just based on the headers, no?
- daveoc64 6y agoThe CDN is not the place you have to worried about. If Site A loads a specific JavaScript file for users with an administrator account, Site B can check to see if the JavaScript file is in your cache, and infer that you must have an administrator account if the file is there. The attack can happen with different types of resources (such as images).
- mmcwilliams 6y agoThis I understand, the risk of third-parties monitoring. The attacks are pretty obvious. My confusion is over what the business model of a commercial CDN is if not to track users across multiple sites? How do they pay for bandwidth?