Re: Fingerprinting users with cached intermediate certificates

Martin Thomson <[email protected]> Wed, 22 Feb 2017 16:33:47 +1100
Newsgroups gmane.comp.mozilla.security
Message-ID <CAPLxc=XCHEW0_Q1TBwq-RLjhdW_eRo75aysnX1NrD192x-BRhw@mail.gmail.com>
On Wed, Feb 22, 2017 at 4:12 PM, Kyle Hamilton <[email protected]> wrote:
> https://shiftordie.de/blog/2017/02/21/fingerprinting-firefox-users-with-cached-intermediate-ca-certificates-fiprinca/

HSTS can be used to do the same without relying on being able to
identify a large set of intermediates that the user hasn't already
seen.  Also, Firefox isn't alone in caching intermediates.  I think
that you will find that other browsers all do the same thing.