You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
If a server sends an Alt-Svc entry that nominates a QUIC version that doesn't actually exist and the client goes with it, there's a tracking risk. The client should never propose a valid version that it doesn't speak, so this isn't 32 bits of tracking, but if the server sends something in the grease range, the client knows it's okay that it doesn't speak it. You still get 16 bits of persistent ID this way.
This can probably be avoided by adding a requirement that the client only use versions from the list that it speaks, and that if it decides to grease it MUST generate its own grease version.
The text was updated successfully, but these errors were encountered:
If a server sends an Alt-Svc entry that nominates a QUIC version that doesn't actually exist and the client goes with it, there's a tracking risk. The client should never propose a valid version that it doesn't speak, so this isn't 32 bits of tracking, but if the server sends something in the grease range, the client knows it's okay that it doesn't speak it. You still get 16 bits of persistent ID this way.
This can probably be avoided by adding a requirement that the client only use versions from the list that it speaks, and that if it decides to grease it MUST generate its own grease version.
The text was updated successfully, but these errors were encountered: