Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Well there is the integrity atttribute. https://www.w3schools.com/Tags/att_script_integrity.asp


Pretty useless in this case if I control the stream going to you. The main page defining the integrity would have to be encrypted.

Maybe you could have a mixed use case page in the browser where you had your secure context, then a sub context of unencrypted protected objects, that could possibly increase caching. With that said, looks like another fun hole browser makers would be chasing every year or so.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: