Not only is it 2.5KB of extra header info sent, but I don't think cloudflare should know which websites their customers have been visiting.
Not only is it 2.5KB of extra header info sent, but I don't think cloudflare should know which websites their customers have been visiting.
I don't see a privacy policy on CDNJS.com. I'd definitely like to know what data they collect about my visitors and what they do with it.
At least the CDN doesn't itself set any cookies.
And note too, that if you're relying on a 3rd party to serve javascript your users are going to run in their browsers - if that 3rd party isn't trustworthy, you're screwed in much worse ways that cookie tracking privacy violations. Who'd notice if they started occasionally serving a modified version of jQuery which sent all form field keydowns (aka, your usernames and passwords) back to theselves?
I think my comment above was too paranoid, as well, but it's too late to edit. All I was suspicious of was that there might be analysis going on.
How does CloudFlare make its money? It's a CDN company. I mean, that's the CORE of what they do. What is jsCDN? It's a CDN.
A simpler theory is that hosting a Javascript CDN (and demonstrating that it's even better than Google's, which is amazing), is going to provide a lot of free advertising for their product. If I use their CDN for JS and it works really well, I'm likely to go back to them for hosting other things, because using jsCDN is almost like doing a free trial of their actual CDN.
It's not even like their main form of income is in another industry that we have to make a cognitive leap to see what their ulterior motives are. It's precisely this. CDNs.
Definitely not very useable for tracking purposes, they will only know about first visit of a user. Even more if sites a and b use the same js library and version, they will only know about the first that a user visit.
Anyway is a bad technical decision not to use a different domain to ensure clients don't need to send extra cookies in the headers.
Though for the most part, people will not have cookies set on the domain unless they have visited the main site (i.e. they are developers).
Or would that mess up cloudflare's anycast DNS?