Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If anything, this is worse.

Cookies have built in browser behavior - they have limited scope, the browser lets you see them, they get cleared out regularly.

Abusing metadata is way sketchier.



Chances are they aren’t the first to come up with something like this. How can we detect this kind of metadata abuse?


perhaps randomize minutes/seconds of the "last-modified" header.


Or perhaps just drop minutes/seconds. And maybe don't store the date altogether for files that are small enough?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: