3 ms·
I still don't really understand why we can't just run any files in cache (from other sites) with the same hash. If I have the sha-256 of an exe file, I'm perfe
by Ellipsis753 11y ago
I still don't really understand why we can't just run any files in cache (from other sites) with the same hash.
If I have the sha-256 of an exe file, I'm perfectly happy to run any exe file with the same sha256 simply because collisions don't happen. Why is this different for JavaScript?
If an attacker can inject HTML script tags into your website haven't you already lost?
- airza 11y agoContent security policy is a defensive technology which makes the answer to your last question "no." Attackers still need to have their script appear to execute from a whitelisted domain, which is only possible if the system you propose is enacted. IE - have your own random webpage which loads a script with hash X, then redirect to an XSS hole which appears to load that script on a client's site that also comes from a whitelisted domain. Since it is cached from the first site, it will be loaded as if it was hosted on the second site and thus bypass CSP.