Hacker News new | ask | show | jobs
by jbert 6418 days ago
Ah, yes. An attacker could fetch the resource themselves, discover the ETag and serve their malicious resource with the real ETag. Sorry.