3 ms·
It sounds like they're talking about ETags [1] here. I don't think JavaScript has anything to do with it. [1] https://en.wikipedia.org/wiki/HTTP_ETag#Typical_u
by goflyapig 6y ago
It sounds like they're talking about ETags [1] here. I don't think JavaScript has anything to do with it.
[1] https://en.wikipedia.org/wiki/HTTP_ETag#Typical_usage https://en.wikipedia.org/wiki/HTTP_ETag#Typical_usage
- simias 6y agoOoh, that's interesting. The way it was described made me think that you needed some JS to check if the data was in cache or not. I guess it's probably a bad idea to let the browser send this type of potentially unique info to the server by default, but I understand how it makes sense from a performance perspective. As far as I'm concerned privacy should always trump performance, but I realize that not everybody shares this point of view.
- yc12340 6y agoETags and Last-Modified headers can be used for long-term user tagging, but without Javascript they provide a lot less value in terms of tracking. Suppose, that you are visiting a web site with Evil Embedding (an iframe tag or script, that loads Evil Resource on behalf of advertiser). If your browser requests Evil Resource without telling advertiser the name of top-level site, the advertiser gets little. They get to know, that user 9062342154 is online and they are asking for Evil Resource X, but that's all. They can't even tell, which specific website is being visited! The real problems start, when the top level web site cooperates with advertiser by running a Javascript "bridge", that acts both as an arbiter and a communication channel for siphoning your information. In addition to transferring information, the bridge acts as anti-fraud measure to confirm, that there is no foul play on the part of web site operator. Since the script is Turing-complete and can be updated anytime, there is no way to restrict it's actions.
- pflanze 6y ago> If your browser requests Evil Resource without telling advertiser the name of top-level site, the advertiser gets little. But the advertiser will get the referrer so will know the domain name? (And if they didn't, they could require the site operator to include the site name in the resource URL.)