3 ms·
That would just make it easier for a MITM (and maybe others) to spoof all your static content with legitimate signatures.
by nicois 11y ago
That would just make it easier for a MITM (and maybe others) to spoof all your static content with legitimate signatures.
- hawski 11y agoNo because your signature should be signed by key registred at CA. It would be second level certificate for your domain. And you would still serve your files via HTTPS. So that would give you second line of defense.