Twitter Direct Message Caching and Firefox
hacks.mozilla.org
hacks.mozilla.org
It looks like "no-store" is in this IETF RFC: https://tools.ietf.org/html/rfc7234#section-5.2.2
EDIT - Ah, I see, it's in the original post:
> Testing from Twitter showed that the request was not being cached in other browsers. This is because some other browsers disable heuristic caching if an unrelated HTTP header, Content-Disposition, is present. Content-Disposition is a feature that allows sites to identify content for download and to suggest a name for the file to save that content to.
> In comparison, Firefox legitimately treats Content-Disposition as unrelated and so does not disable heuristic caching when it is present.
It looks like Twitter only tested this in Safari and Chrome and called it a day. Their wording implies that it's Firefox's fault, which is misleading.
What’s going to happen when someone decides that browsers must have content restrictions?
It amazes me how willing some people on HN just willingly give up their freedom to the government.
NIST for one.
Even when you do have competent people in the government like in the CDC, they are still hamstrung by the ideology of the executive branch.
However, I am not so sure that such a thing is even necessary at all. I think the use of the web browser should be reduced in order that this is not necessary.
Devs can still make browsers explicitly for other devs or for non-public use. If society depends on your product to function then your product must be regulated. Imagine google auto-updates chrome to stop supporting http or something, imagine the economic chaos. The whims of Googlers are not something the public should rely on. Everything from their standards compliance to their change control should be regulated,same goes for mozilla.
> What’s going to happen when someone decides that browsers must have content restrictions?
You're joking right? You think the government can't do that already? Ok,let's see the logic here , let's say that's the case. What happens when Google decides to have content restrictions? Nothing! It's not regulated activity so it falls under Google's freedom of speech,they can restrict any content they want. However b.s. it might be, in theory at least you have some control over your government. Google does what is in their best business interest, you are the product, advertisers are their customers.
Your illusion of freedom is to have your own government as far away as possible. Would you be comfortable if General Motors or Ford decided the safety standard or road-readiness of cars? Certainly you can't have government take away your freedoms by telling them what is safe and acceptable for the general public to use? What if the government decides to have them restrict cars from driving to certain places!
You really have no idea how many seniors don’t have internet access. I don’t think a browser not properly supporting the CSS box model will kill anyone....
What happens when Google decides to have content restrictions? Nothing! It's not regulated activity so it falls under Google's freedom of speech,they can restrict any content they want.
How can Google restrict the websites I go to?
However b.s. it might be, in theory at least you have some control over your government. Google does what is in their best business interest, you are the product, advertisers are their customers.
As if government officials don’t do what’s in their own best interest. Because of the way that both the electoral college and the Senate is designed, if you live in a more populous state, you will always have less voting power than someone in “Middle America.” Not to mention gerrymandering.
So exactly how does a browser not adhering to standards affect my survival?
Your logic can apply to healthcare as well. Plenty of healthy people. Plenty of people have good jobs and insurance. So does that mean healthcare affordability for everyone should not be regulated?
Oh and the whole electoral college b.s., so you're saying we should disband FTC,FDA,EPA and all other regulatory agencies as well? Come on!
> How can Google restrict the websites I go to?
Easy, they can block it out right or simply deprecate support for the site. A close-enough example is ublock origin and how google basically crippled their ability to block ads. Were there regulations, it would not be up to google. The first thing that should be regulated is their ability to deprecate random things on a whim.
This is the same government whose ancient COBOL systems can’t handle the influx of unemployment claims and their is a submission currently on the front page of HN about one agency forcing people to fax a claim in.
But I think WWW is too messy and complicated. Better is to not require a web browser at all, if it can be avoided. (There is also gopher, telnet, postal mail, etc, depending what you need. The web pages can still be provided as an option, of course.)
Since origin servers do not always provide explicit expiration times,
a cache MAY assign a heuristic expiration time when an explicit time
is not specified, employing algorithms that use other header field
values (such as the Last-Modified time) to estimate a plausible
expiration time. This specification does not provide specific
algorithms, but does impose worst-case constraints on their results.
The standard does not say what heuristics should be used, so Firefox’s heuristics is no more “legitimate” than Chorme/Safari’s heuristics of expiring immediately when Content-Dispostion is present.“Firefox legitimately treats...” is highly misleading, making it sound like Firefox is more standard-compliant, but it’s not; it’s just different.
I feel like the author was anticipating a lot of people blaming Firefox for this incident, and is attempting to shut those responses before they get made.
I think that trying to write to the responses you expect from your audience unfortunately ends up with these kinds of miscommunications of intention more often than not.
(Disclosure: I work for Google)
In other words, rather than checking with the standard how to indicate that content should not be cached, they simply checked whether Chrome did not cache it, and since it didn't, decided that whatever they were doing was the way to prevent caching.
(a) - Firefox users &&
(b) - who downloaded their messaging history on a buried menu option in the account page &&
(c) - in the last 7 days prior to disclosure &&
(d) - who did this on a computer where someone else has access
The number of affected people is presumably very small, and the only metric that twitter can't know here is (d). How on earth does it make sense to alert every Firefox user with a scary wall of text? Don't they have logs to cross-reference (a), (b) and (c) and e-mail these users?
I'd believe that if there's only one API endpoint that would be crucial to log to protect against major leaks, it would be this one to download all your history at once...
I also didn't see any notice, but I don't know if I missed it, my adblocker ate it, or if they actually did only inform users that did one of the at-risk things and I happened to not do so.
So yeah, no surprise that they would blame others for their failings.
Pasting an URL into a tweet entry form in their web client has been resulting in "Something went wrong" in 50% of cases for several months now. Attaching a GIF to a tweet randomly fails with no explanation given, again - for months.
I don't know what Twitter's development priorities are, but they sure as hell don't include proper web client testing.
One thing I did use to repro though was text field behaving erratically on Firefox Mobile or when using installed PWA from home screen. Had to give up and use Chrome directly.
content-disposition: attachment; filename=json.jsonSending it as a "file download" has no effect on what happens when the endpoint is called via AJAX, but in the event that a browser navigates to it directly, ensures that even the dumbest of browsers do not render it as HTML.
https://w3c.github.io/webappsec-clear-site-data/#example-sig...
I was thinking that a rendering bug (which is what one expects from a browser compatibility bug) is not that bad, but when we are talking privacy and security, now that's a problem.