Hacker News new | ask | show | jobs
by tomvangoethem 3536 days ago
Attaching cookies to third-party requests is the source of many issues. In a similar demonstration [0], I showed that browser-based timing attacks (which can probably be considered as wont-fix as well) can be used to extract more specific information from social networks (e.g. one's political preference based on who they're following).

[0]: https://labs.tom.vg/browser-based-timing-attacks/