Lapho kuxoxwa
Isihloko se-X-Client-Data asikona ukusebenza okufihliwe futhi nokuziphatha kwayo
unhlokweni
Unhlokweni kuthiwa awuqukethe ulwazi lomuntu siqu olungakhonjwa futhi uchaza kuphela isimo sokufakwa kwe-Chrome nezici zokuhlola ezisebenzayo. Uma i-telemetry yokusetshenziswa kwesiphequluli nokubikwa kokusaphazeka kukhutshaziwe kuzilungiselelo, ukukhiqiza inani lesihloko le-X-Client-Data eliyisisekelo kusebenzisa amabhithi angu-13 kuphela e-entropy (izinhlanganisela ezihlukene ezingu-8000), anele ukuhlonza.
Uma kucatshangelwa ukuthi unhlokweni uphinda ubhale ezinye izilungiselelo zesistimu namapharamitha, ekugcineni okuqukethwe kwe-X-Client-Data kufanelekile njengomthombo owengeziwe wedatha yokuhlonza umsebenzisi ongaqondile ngesikhathi esifushane (amakhono okuhlola anikwe amandla futhi akhutshaziwe ngokuhamba kwesikhathi, okuholela ekushintsheni kwenani ngezikhathi ezithile ku-X-Client-Data).
Kodwa-ke, ngaphezu kwe-entropy yokuqala, lapho kukhiqizwa inani le-X-Client-Data, kukhona nokulandelana kwembewu okubuyiswe amaseva e-Google futhi kuye ngezwe, ikheli le-IP nezinye izindlela i-Google ezibona zibalulekile (ngokwesibonelo, akukho lutho oluvimbelayo. wena ekubuyiseleni ukulandelana okukhulu okungahleliwe , okuzoba yikhombi ngqo).
Ngaphezu kwalokho, ukuhlola usebenzisa imaski yesizinda se-Google lapho uthumela i-X-Client-Data akubandakanyi izimo lapho umhlaseli engabhalisa khona isizinda esifana nokuthi βyoutube.xn--55qx5dβ futhi aqale ukuqoqa izihlonzi.
Source: opennet.ru