3 ms·
I feel like this is just another reason to use subresource integrity on your includes. If you are only pulling javascript and your HTML is served outside of Chi
by cakeface 9y ago
I feel like this is just another reason to use subresource integrity on your includes. If you are only pulling javascript and your HTML is served outside of China you can ensure the correctness of the response.
- taf2 9y agoDoesn't the resource still need to be requested to perform the integrity check? If I recall correctly the script was being redirected to a github gist which is why it was effectively a DDOS on github... so yes sub-resource integrity is great but wouldn't protect against this type of attack since the requester was the target of the attack but rather the source...
- JohnTHaller 9y agoThis particular attack had China inserting a javascript reloader into Baidu's javascript file to hit the two github projects they didn't like to perpetrate the DDoS. So, it wasn't just a redirect.