authority's userinfo?

On Thu, Jun 11, 2020 at 01:34:12AM +0200, Petite Abeille wrote:
> Actually, it could be used to fingerprint gemini clients automatically:
> 
> C: gemini://mozz.us/  
> S: 30 gemini://cookie at mozz.us/ 
> C: gemini://cookie at mozz.us/
> S: 20 text/gemini 
> => gemini://cookie at mozz.us/beer/
> 
> A magic cookie!

This is possible regardless using query strings, or even more
obnoxiously, dynamic paths/links. At the end of the day all you can do
is call out dodgy behaviour, and if site owners tried it anyway,
attempt to make this sort of thing visible to client users.

Cheers, Tom

---

Previous in thread (10 of 26): 🗣️ Petite Abeille (petite.abeille (a) gmail.com)

Next in thread (12 of 26): 🗣️ Petite Abeille (petite.abeille (a) gmail.com)

View entire thread.