Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

On the other hand, now that we know about it is easy to defeat: a privacy conscious browser will just add a random amount of minutes/seconds in the “if modified since” header. The only risk is you sometimes trigger a reload because the resource was modified in that interval.


It's harder, but you still leak bits of informations. If the random function is known, statical analysis can still leak out a bit of information.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: