|
|
|
|
|
by cesarb
3013 days ago
|
|
Wouldn't that be a bit of a privacy leak? If 0rrt works, it was a request for a static asset. Of course, TLS is not only for privacy reasons, but also for integrity reasons (preventing injection of malicious Javascript and similar attacks). For that purpose, 0rtt for static assets works fine. |
|
Response size and timing probably already leak this.