melo936 / ChromiumHardening

GNU General Public License v3.0
105 stars 12 forks source link

About QUIC #7

Closed sr093906 closed 3 years ago

sr093906 commented 3 years ago

QUIC is recommended for performance consideration but a paper found it is much easier to fingerprint than HTTPS. It may be better to remind users of the issue.

https://www.theregister.com/2021/01/30/quic_fingerprinting_flaw/

melo936 commented 3 years ago

Thanks for the information @sr093906 !

Used to have a note for QUIC, will add it back.

sr093906 commented 3 years ago

Added.

melo936 commented 2 years ago

Disabling it shouldn't be necessary anymore, because NetworkIsolationKey already partitions alt-svc.