<script src=foobar.js>
Where foobar.js just returns something like "var id=0x1234567", the user who doesn't want to be fingerprinted cannot cache this script because it could be uniquely generated.
<script src=foobar.js>
Where foobar.js just returns something like "var id=0x1234567", the user who doesn't want to be fingerprinted cannot cache this script because it could be uniquely generated.
I think there is a chicken and egg here combined with IP incentives to not fix how web browsers work.
I hoped the great firewall would have accidentally fixed this by making it preferable to refer to hashes that can be found in peer caches irregardless of CDN status.
There is no easy fix to this.
The most anonymity concious would realize they are trying to do banking in what is supposed to be their anonymous session and never fetch the file.. if they somehow missed that they were entering auth details?
The way things need to work on the web involve choices that you apply differently (or IE applies for Windows users.) The defeatist response is not to implement any choices. A typical user will want a small number of PII sites, so let's have only PII mode and autofill their details into forms in any blog!
Am I missing something here?
For example, "weather_at_your_geoip.js".
If it's not cached, then it has to be fetched synchronously for anything depending on its value to work - so it's slow.
If it is cached, then the cached value is known.
If the JS triggers another download, and the browser requests the second resource before the initial JS is done downloading...