4 ms·
> The 0-RTT feature in QUIC allows a client to send application data before the handshake is complete. This is made possible by reusing negotiated parameters fr
by amenod 5y ago
> The 0-RTT feature in QUIC allows a client to send application data before the handshake is complete. This is made possible by reusing negotiated parameters from a previous connection. To enable this, 0-RTT depends on the client remembering critical parameters and providing the server with a TLS session ticket that allows the server to recover the same information.
Am I missing something, or is this yet another way to track clients across visits? If so, I'm sure Chrome will be faster than Firefox (because it will keep the sessions IDs live forever). Well played, Google.
- stusmall 5y agoThere are features that go back a ways in TLS that someone could use for tracking. A while back I wrote a quick and dirty POC for using TLS 1.2 session resumption for sub-NAT user tracking[1]. While it is really effective at separating out multiple different users interacting with a server from behind a NAT, I'm not sure these features are usable for cross site tracking. I'm not familiar with 0-RTT but sessions resumption scoped tickets to a host so it wouldn't be useful there. While someone could use it for some tracking purposes it really is a huge performance boon. There are good intentions on why these features were put in even if they can be abused. 1. https://stuartsmall.com/tlsslides.odp https://stuartsmall.com/tlsslides.odp https://github.com/stusmall/rustls/commit/e8a88d87a74d5630227ea330cc4bf3fae8727b8e https://github.com/stusmall/rustls/commit/e8a88d87a74d563022...
- youngtaff 5y agoSession resumption could be used for cross-site tracking As a mitigation Chrome (and FF?) have started to partition connections so a different connection would be used to a common 3rd party from different top level origins