Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

WRT the "timing attack":

In most cases, client does not even request bytes from CDN which is then not able to track Client. But then again CDNs can implement tracking based on this lack of requests (which is kind of ironic and should be infeasible the more clients use this technique I think).

Actually the other issues are solved by the "DHT" part of this idea: no centralized party can track which assets are already in your history.

The only tracking I can think of is by your nearest neighbours's browsers. If such a neighbour N empties your cache (DNS attack?) it will trigger a full fetch from N. Then N can attempt to fingerprint this assets query with what other pages list. But then the whole point of this is to cache assets that are used on most pages!

I love this idea. Let's make the Web decentralized again! (I couldn't resist)



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: