3 ms·
The problem this solves is even worse than it sounds - there's no reason why the NSA couldn't force a CDN to silently concatenate their own analytics onto a sit
by cantagi 11y ago
The problem this solves is even worse than it sounds - there's no reason why the NSA couldn't force a CDN to silently concatenate their own analytics onto a site's JQuery. Is there a good way of signing your assets?
- mintplant 11y agoSubresource Integrity: https://developer.mozilla.org/en-US/docs/Web/Security/Subresource_Integrity https://developer.mozilla.org/en-US/docs/Web/Security/Subres...
- cuonic 11y agoThere is, and it's called Sub-resource integrity: http://www.w3.org/TR/SRI/ http://www.w3.org/TR/SRI/ MaxCDN's Bootstrap CDN implements it for example: <link href="https://maxcdn.bootstrapcdn.com/bootstrap/3.3.6/css/bootstrap.min.css" https://maxcdn.bootstrapcdn.com/bootstrap/3.3.6/css/bootstra... rel="stylesheet" integrity="sha256-7s5uDGW3AHqw6xtJmNNtr+OBRJUlgkNJEo78P4b0yRw= sha512-nNo+yCHEyn0smMxSswnf/OnX6/KwJuZTlNZBjauKhTK0c+zT+q5JOCx0UFhXQ6rJR9jg6Es8gPuD2uZcYDLqSw==" crossorigin="anonymous">
- micro-ram 11y agoHere is a one line Linux/OSX script that builds the sub-resource integrity hash string of js & css files. https://gist.github.com/anonymous/e05e0ff71993d6a6d757 https://gist.github.com/anonymous/e05e0ff71993d6a6d757