But if you do 1 second granularity a mere 2 cache timestamps are enough to fingerprint everyone on the planet, each day.
is my math wrong, here?
[1]: https://www.privoxy.org/user-manual/actions-file.html#OVERWR...
This allows site owners get statistics on page views/uniques/bounces without unique identifier cookies or javascript injections.
I’m all for blocking any abusive tracking methods, but this looks to me like creative website statistics that works for single domain. What’s the harm by measuring that?
What’s the motivation to submit to it?
If you can allow them to do that without getting tracked, it’s win-win. You get a better experience when they build a better service.
If I fetch your /foo.html today in November 2022, and you send me a last-modified from 1978, that gives me and my UA a huge range from which to select a different datetime (anywhere between the 1978 value and now-ish) on my next request. How are you going to correlate my original and subsequent requests if in the latter I ask if you've got a copy that's been modified since 1999?
But users go to the web with the browser they've been given.
Apple, famously, forbids its users to speak HTTP with anything else on iOS.
An acceptable response, then (to both you and the original commenter), follows: "While some particular browser version doesn't currently protect individuals from that proposed form of tracking, any browser vendor could trivially start thwarting that form of tracking by exploiting the latitude afforded to UAs by the semantics of these headers." And that's the form that the previous comment takes and how it should be understood. The fact that "users go to the web with the browser they've been given [i.e., today, and which isn't providing this sort of tracking protection]" doesn't change anything; we are explicitly talking about steps that each side _can_ take in the arms race related to the subject of this discussion...