3 ms·
There is no such mechanism in TLS, but HTTP Range header and wikipedia supports it. So if you want to be protected agains this side-channel problem you can use
by uuidgen 5y ago
There is no such mechanism in TLS, but HTTP Range header and wikipedia supports it.
So if you want to be protected agains this side-channel problem you can use Connection: Keep-Alive header along with Range header to split each request into a few Range requests.
As TLS pads data to the block size you can introduce uncertainty of 0-8 bytes per chunk. Put some random delays between chunks and while it will be slower and with a bit higher overhead passive attacker won't tell if you're requesting one article in chunks or a few other.
And all this can be implemented client-side.