5 ms·
How does the law differentiate that from jQuery on a CDN? The CDN is also doing some amount of tracking, and some of it is simply technically necessary. Google
by throwaway3306a 2y ago
How does the law differentiate that from jQuery on a CDN? The CDN is also doing some amount of tracking, and some of it is simply technically necessary. Google is actually using the Google Fonts service to track traffic.
- mdavidn 2y agoA CDN delivering something like jQuery will not receive cookies nor query parameters and will return a very generous max-age, allowing the browser to reuse the resource for any number of pages or sites without contacting the CDN again. The value of CDNs like this has diminished greatly with the advent of HTTP/2 and HTTP/3.
- hunter2_ 2y agoBut it could start delivering not-jQuery at some point. Far-fetched on the surface, but it's exactly what occurred with polyfill.io recently: https://blog.qualys.com/vulnerabilities-threat-research/2024/06/28/polyfill-io-supply-chain-attack https://blog.qualys.com/vulnerabilities-threat-research/2024... https://news.ycombinator.com/item?id=40791829 https://news.ycombinator.com/item?id=40791829
- mdavidn 2y agoThis is true, but there is a mitigation available: The site can require the resource to match a specified cryptographic hash before running. This did not work with polyfill.io because that CDN would dynamically return different resources based on the user agent. https://developer.mozilla.org/en-US/docs/Web/Security/Subresource_Integrity https://developer.mozilla.org/en-US/docs/Web/Security/Subres...
- rvnx 2y agoTechnically CDNs are not needed, we could just fully drop CDNs as well and cache files by content hash in the browser across multiple sites (<script hash="AAAAAAAAA" fallback="https://cdn..."></script> https://cdn..."></script>, instead of by path). It would make the web faster and reduce tracking. Now, is that really what Google Fonts or Cloudflare CDN wants ? Maybe, but it will reduce the amount of data shared to the intelligence groups.
- Lukas_Skywalker 2y agoCaching across sites is a privacy risk in itself, because scripts can measure the time required to load a resource and therefore detect if a visitor has visited another site with the same resource before. That‘s why modern browsers no longer cache across sites. https://news.ycombinator.com/item?id=24894135 https://news.ycombinator.com/item?id=24894135
- dotancohen 2y agoWhy not add a random 1000-3000 ms delay to making the cached resource available? Timing attacks are not a new phenomenon.
- minitech 2y agoBecause the point of cache is to save time, not waste it. Like most naïve delays in response to timing attacks, that also doesn’t solve the tracking problem – if there’s any detectable difference (consider a cross-site tracking server that serves the content with a controllable delay) under any circumstances (consider network and disk load and availability), the mitigation is defeated. Sites don’t share that many resources byte-for-byte anyway. The current solution is fine.
- dotancohen 2y agoCaches also save bandwidth - for the user, for the server, and for the potentially overloaded network as well.
- fn-mote 2y agoRandom delays don’t stop timing attacks. You just need to gather more data before your estimate of the “unrandomized timing” is good enough for you to make your conclusions.
- cqqxo4zV46cp 2y agoIt’s hilarious that your off-the-cuff solution to “stopping data being shared to the intelligence groups” is itself reintroducing a known and now-mitigated security vulnerability. This stuff isn’t easy. HN has way too big a head.
- digging 2y agoI mean I'm not writing a literal law, but that would be roughly illegal and punishable in my fantasy world where a right to digital privacy existed. Laws, as a rule, don't physically stop anyone from doing anything they want. Plenty of illicit things happen on the internet already.
- digging 2y ago> How does the law differentiate that from jQuery on a CDN? The CDN is also doing some amount of tracking, and some of it is simply technically necessary. I don't know, it might be an intractable problem. It sucks how there's no way to tell the difference between the payloads of two different 3rd party scripts when they're executed in the browser, huh?
- tmoertel 2y ago> Google is actually using the Google Fonts service to track traffic. According to https://developers.google.com/fonts/faq/privacy#when_i_embed_google_fonts_in_my_website_via_the_google_fonts_web_api_what_data_does_google_receive_from_my_website_visitors https://developers.google.com/fonts/faq/privacy#when_i_embed..., "For clarity, Google does not use any information collected by Google Fonts to create profiles of end users or for targeted advertising."
- g15jv2dp 2y agoAh, well, if it's written in a FAQ, then the most naive interpretation of the sentence must be true. No way they'd just lie or pull off a "trickster genie" interpretation of that sentence.
- throwaway3306a 2y agoI'm sure they don't. That's also not the only thing you do with tracking.
- BeFlatXIII 2y ago> How does the law differentiate that from jQuery on a CDN? Functional utility for the end user
- throwaway3306a 2y agoSo the solution is to combine them?