3 ms·
This "feature" is also a major downside... protocol level user tracking. See https://svs.informatik.uni-hamburg.de/publications/2019/2019-07-17-Sy-A_QUIC_Look_a
by frmdstryr 5y ago
This "feature" is also a major downside... protocol level user tracking. See https://svs.informatik.uni-hamburg.de/publications/2019/2019-07-17-Sy-A_QUIC_Look_at_Web_Tracking_PETS_2019.pdf https://svs.informatik.uni-hamburg.de/publications/2019/2019...
- mgrund 5y agoAbsolutely not a coincident that Google is proposing a protocol that allows protocol level user tracking. By making the session ticket server-initiated and not client-controlled all control is also stripped from the user.
- ithkuil 5y agoThe clients are free to make another "connection" and get a new session id every time they want. It's similar to http connection reuse: the src ip-port + dst-port also acts as a "session identifier", as long as multiple requests flow throug the same TCP connection.
- josefx 5y agoBrowsers are also free to use per site caches instead of a global one and sadly we ended up with just that because it turns out you cannot trust the internet with user privacy in any way.
- ilove196884 5y ago
- joveian 5y agoTLS has session resumption with exactly the same issues, it is just more efficient in QUIC.