5 ms·
There is/was discussion in the standards body of using the SRI hash for exactly this purpose. It sounds really promising but iirc there was a privacy kink to wo
by Scott_Helme_ 9y ago
There is/was discussion in the standards body of using the SRI hash for exactly this purpose. It sounds really promising but iirc there was a privacy kink to work out.
- sago 9y agoYou could potentially tell whether someone has been to a third-party site. Person goes to a porn site, get's file #A. Spying site, offers file #A, but never delivers it. If a person already has #A (i.e. doesn't request it), spy site knows they've been to porn site.
- deleted 9y ago[deleted]
- stordoff 9y agoCould you limit it to widely used libraries? e.g. browser ships with the last N versions of jQuery etc., and avoids the request if it's a known hash. If it's widely used, it seems like the amount of information leaked would be low, and if the browser _always_ ships with it (rather than caching on first use), it would only identify the browser and not browsing history anyway. As a bonus, developers could use it knowing that there is much less likely to be a performance hit from fetching it.