3 ms·
I think the comments on this post would probably less hostile if the title said something like "detect the number of unique visitors", which is what I believe i
by glenjamin 4y ago
I think the comments on this post would probably less hostile if the title said something like "detect the number of unique visitors", which is what I believe it's doing, rather than detecting unique visitors using unique timestamps, which is what many seem to be guessing based on the headline alone.
- michaelbuckbee 4y agoThey're using this to track number of unique visits from a single user to a site.
- Thorrez 4y agoYes, but I think they're not tracking anything else about the user besides number of visits. E.g. they're not tracking ip I don't think. And I think they are only doing it within a single day, not across days. If you know that someone exists who visited your site 500 times today, but know nothing else about the person, is that a privacy problem?
- tedunangst 4y agoYour personal visit count is embedded in the seconds.
- lisper 4y agoYes, but not your identity.
- andix 4y agoIt would be interesting if it is also possible to abuse it. If it is possible to create enough unique timestamps, that browsers still accept them. Can you add milliseconds to the TS, and do browsers store them too? Or do browsers also accept timestamps from months or years back and re-send them? If you can use the whole scale of Unix time (int32), there is a huge pool of entropy available. In this case they don’t do this evil thing, and it probably would still violate the European GDPR, even if it’s not an actual cookie, but somebody has to find it first.
- kapep 4y agoEven without millisecond precision, you could embed multiple assets that are served with slightly different timestamps to encode a unique identifier.