4 ms·
This is really no different than a cookie - basically the same mechanism from the view of the server just different semantics.
by Isinlor 4y ago
This is really no different than a cookie - basically the same mechanism from the view of the server just different semantics.
- ape4 4y agoYes, cookies are a header field sent back by the browser and so is this.
- legitster 4y agoIf anything, this is worse. Cookies have built in browser behavior - they have limited scope, the browser lets you see them, they get cleared out regularly. Abusing metadata is way sketchier.
- eurasiantiger 4y agoChances are they aren’t the first to come up with something like this. How can we detect this kind of metadata abuse?
- fanso99 4y agoperhaps randomize minutes/seconds of the "last-modified" header.
- notpushkin 4y agoOr perhaps just drop minutes/seconds. And maybe don't store the date altogether for files that are small enough?
- pornel 4y agoImportant to note that privacy laws that regulate tracking are not limited to the Cookie header. They apply to tracking and data collection in general, regardless of how technically clever you make it.
- pavon 4y agoExactly. They could have the same functionality and privacy characteristics if they simply kept a cookie that incremented each time the site was visited. The fact that they didn't go this route suggests this is more about finding a way to track unique visitors when cookies are disabled. They are deliberately subverting the user's desire to not be tracked and spinning it as a privacy win.
- dahfizz 4y agoIf it was about tracking users, wouldn't they generate a unique timestamp per visitor on the first visit? Giving everyone the same timestamp is a terrible way to try and track individuals.
- dvko 4y agoThis is part of why I quit my privacy focused analytics start-up years ago. I won’t name it directly, but it was one of the first and is still going strong (although not really open-source anymore). People kept asking for cookieless tracking but with another way of identifying returning visitors that was always worse from a privacy standpoint. Cookies can be controlled by the client, anything stored on the server can not. Honestly, cookies are pretty nice, it’s the law around this that sucks. Tricks that attempt to bypass the laws will surely only work for a limited time, at least I hope they will…
- geocar 4y agoWell, yes you could have a cookie with C=C+1 and carefully set the expiration to the end of the day (like the article), or you could use randomly generated last-modified times and deduplicate server-side (similar to how cookies are usually used), but I can think of a few reasons the cache would give greater precision, so even if a lot of the same things are the same, I'm not so sure it's really "no different"; these things are pretty important to (some) publishers: - third-party cookie blocking/notification features in browsers - review processes on ad networks checking for actual cookies rather than suspicious last-modified times