Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

In fact there is a new feature Chrome is championing (and just shipped) called "Compression dictionary transport" - https://datatracker.ietf.org/doc/draft-ietf-httpbis-compress... / https://chromestatus.com/feature/5124977788977152 that allows any HTTP resource to specify the dictionary it wants to use (including the "use me as the dictionary for future reuqests") which allows a website to use a dictionary that specialized to _its_ contents instead of the contents of something completely different.


Another state machine in the browser what can go wrong


Heh and if dictionaries can be shared between sites, another potential security leak.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: