Does not seem like a big deal to me; because it's unlikely to work outside a lab environment, nor passed the first 256 bytes (without a truly massive amount of connections at least).<p>And all that work for what - to sniff out your own cookie?<p>I mean, what is this good for, it's not a man-in-the-middle attack, it's not a spoofing attack, etc?<p>*Though it's really good work on the researchers part, and the author of the article explained it all in an excellent way.