3 ms·
This is true, but there is a mitigation available: The site can require the resource to match a specified cryptographic hash before running. This did not work w
by mdavidn 2y ago
This is true, but there is a mitigation available: The site can require the resource to match a specified cryptographic hash before running. This did not work with polyfill.io because that CDN would dynamically return different resources based on the user agent.
https://developer.mozilla.org/en-US/docs/Web/Security/Subresource_Integrity https://developer.mozilla.org/en-US/docs/Web/Security/Subres...
- rvnx 2y agoTechnically CDNs are not needed, we could just fully drop CDNs as well and cache files by content hash in the browser across multiple sites (<script hash="AAAAAAAAA" fallback="https://cdn..."></script> https://cdn..."></script>, instead of by path). It would make the web faster and reduce tracking. Now, is that really what Google Fonts or Cloudflare CDN wants ? Maybe, but it will reduce the amount of data shared to the intelligence groups.
- Lukas_Skywalker 2y agoCaching across sites is a privacy risk in itself, because scripts can measure the time required to load a resource and therefore detect if a visitor has visited another site with the same resource before. That‘s why modern browsers no longer cache across sites. https://news.ycombinator.com/item?id=24894135 https://news.ycombinator.com/item?id=24894135
- dotancohen 2y agoWhy not add a random 1000-3000 ms delay to making the cached resource available? Timing attacks are not a new phenomenon.
- minitech 2y agoBecause the point of cache is to save time, not waste it. Like most naïve delays in response to timing attacks, that also doesn’t solve the tracking problem – if there’s any detectable difference (consider a cross-site tracking server that serves the content with a controllable delay) under any circumstances (consider network and disk load and availability), the mitigation is defeated. Sites don’t share that many resources byte-for-byte anyway. The current solution is fine.
- dotancohen 2y agoCaches also save bandwidth - for the user, for the server, and for the potentially overloaded network as well.
- fn-mote 2y agoRandom delays don’t stop timing attacks. You just need to gather more data before your estimate of the “unrandomized timing” is good enough for you to make your conclusions.
- cqqxo4zV46cp 2y agoIt’s hilarious that your off-the-cuff solution to “stopping data being shared to the intelligence groups” is itself reintroducing a known and now-mitigated security vulnerability. This stuff isn’t easy. HN has way too big a head.