Hacker News new | ask | show | jobs
by semi 743 days ago
The privacy issues aren't just hypothetical, but that aside, that caching model unfortunately doesn't mesh well with modern webdev. It requires all dependencies to be shipped in full, no tree shaking to only include the needed functions. And separately as individual files.. and for people to actually stick to the same versions of dependencies
1 comments

Can you show some real sites that were mounting such attacks using libraries?