Whereas anchors tend to be generic (#preexisting-conditions), this new scroll behavior can be used to create an existence check for any user-specific text on the page (in carefully crafted scenarios). There are probably other variations that could be devised on this concept, since it allows indirect page interaction that can bypass authorization walls (since the browser would transmit cookies normally and such).
I'd like to call myself a privacy advocate, but this is just absurd. The pros obviously outweigh the con of a very precise and targeted attack that leaks a predetermined bit of information.
If you've got their DNS records, you've already violated plenty of their privacy to get the information you want. No need for this text fragment "attack."
Yeah, my read of this is that it has nothing to do with privacy, people who want to block change for some reason have just learned that "i have privacy concerns about google" is a catchword that will get you some press coverage, and are essentially hijacking the actually valid and important privacy concerns to push forward their unrelated opinions (and promote their browser product).
As a FF user, I'd love to see FF implement this too!
This would behave differently if the browser's user is following @user than otherwise.
This convinced me not to dismiss the issue. I'm not sure how that leaks over a side channel. But i am sure there are governments who take active measures to shape the Internet to their liking - and twitter has played a significant role in the past inside countries governed by them to oppose these governments.