5 ms·
A CDN delivering something like jQuery will not receive cookies nor query parameters and will return a very generous max-age, allowing the browser to reuse the
by mdavidn 2y ago
A CDN delivering something like jQuery will not receive cookies nor query parameters and will return a very generous max-age, allowing the browser to reuse the resource for any number of pages or sites without contacting the CDN again.
The value of CDNs like this has diminished greatly with the advent of HTTP/2 and HTTP/3.
- hunter2_ 2y agoBut it could start delivering not-jQuery at some point. Far-fetched on the surface, but it's exactly what occurred with polyfill.io recently: https://blog.qualys.com/vulnerabilities-threat-research/2024/06/28/polyfill-io-supply-chain-attack https://blog.qualys.com/vulnerabilities-threat-research/2024... https://news.ycombinator.com/item?id=40791829 https://news.ycombinator.com/item?id=40791829
- mdavidn 2y agoThis is true, but there is a mitigation available: The site can require the resource to match a specified cryptographic hash before running. This did not work with polyfill.io because that CDN would dynamically return different resources based on the user agent. https://developer.mozilla.org/en-US/docs/Web/Security/Subresource_Integrity https://developer.mozilla.org/en-US/docs/Web/Security/Subres...
- rvnx 2y agoTechnically CDNs are not needed, we could just fully drop CDNs as well and cache files by content hash in the browser across multiple sites (<script hash="AAAAAAAAA" fallback="https://cdn..."></script> https://cdn..."></script>, instead of by path). It would make the web faster and reduce tracking. Now, is that really what Google Fonts or Cloudflare CDN wants ? Maybe, but it will reduce the amount of data shared to the intelligence groups.
- Lukas_Skywalker 2y agoCaching across sites is a privacy risk in itself, because scripts can measure the time required to load a resource and therefore detect if a visitor has visited another site with the same resource before. That‘s why modern browsers no longer cache across sites. https://news.ycombinator.com/item?id=24894135 https://news.ycombinator.com/item?id=24894135
- dotancohen 2y agoWhy not add a random 1000-3000 ms delay to making the cached resource available? Timing attacks are not a new phenomenon.
- minitech 2y agoBecause the point of cache is to save time, not waste it. Like most naïve delays in response to timing attacks, that also doesn’t solve the tracking problem – if there’s any detectable difference (consider a cross-site tracking server that serves the content with a controllable delay) under any circumstances (consider network and disk load and availability), the mitigation is defeated. Sites don’t share that many resources byte-for-byte anyway. The current solution is fine.
- dotancohen 2y agoCaches also save bandwidth - for the user, for the server, and for the potentially overloaded network as well.
- fn-mote 2y agoRandom delays don’t stop timing attacks. You just need to gather more data before your estimate of the “unrandomized timing” is good enough for you to make your conclusions.
- cqqxo4zV46cp 2y agoIt’s hilarious that your off-the-cuff solution to “stopping data being shared to the intelligence groups” is itself reintroducing a known and now-mitigated security vulnerability. This stuff isn’t easy. HN has way too big a head.
- digging 2y agoI mean I'm not writing a literal law, but that would be roughly illegal and punishable in my fantasy world where a right to digital privacy existed. Laws, as a rule, don't physically stop anyone from doing anything they want. Plenty of illicit things happen on the internet already.