Hacker News new | ask | show | jobs
by fbrchps 1215 days ago
The security implications of "find me another device on this network who has gone to a specific page" are immense. Not to mention accessing account-related information due to improper no-cache headers on the website.
2 comments

Only applications where I could see the tradeoffs be worth it is over satellite links.

Either that or game/code assets on large college or corporate campuses.

There are lots of grade schools with slow internet, and when OS updates come out, all the kids open their school laptops and get prompted to update, which basically ends the class immediately because the slow pipe can't service 25 identical hundred-megabyte downloads quickly.
there are plenty of more plausible misconfiguration risks that we accept, or consider the operators responsible. i'm not sure why you would take issue with this one.

additionally, content-addressing provides another layer of security beyond location addressing. even improperly cached information is as secure as your hashing algorithm.