Re: [Proposal]: Set origin-wide policies via a manifest.

On Thu, Jul 28, 2016 at 2:58 PM, Mike O'Neill
<michael.oneill@baycloud.com> wrote:
> Giving a privacy aware user potentially worse performance is problematic, though I expect it would be rare. But this still suffers from the transparency argument, how does the user know that an origin has made the Origin-Policy response have a  UID in it. An alternative maybe to use the cookies. If the cookies are present (not blocked) then one of them could be Cookie: __Origin-Policy: I-want-this-one then the server sees that and supplies that version along with its hash in the request header. The user is no worse off privacy wise because they can use the browser UI to see what’s happening, and there hasn’t been yet another possible fingerprint vector created.

I don't see how that's an alternative. If they are blocked you still
get worse performance.


-- 
https://annevankesteren.nl/

Received on Thursday, 28 July 2016 13:03:57 UTC