5 ms·
Have a look at https://w3c.github.io/webappsec-subresource-integrity/ https://w3c.github.io/webappsec-subresource-integrity/
by syoc 8y ago
Have a look at https://w3c.github.io/webappsec-subresource-integrity/ https://w3c.github.io/webappsec-subresource-integrity/
- tlrobinson 8y agoThat’s a start, but if the main resource (the HTML page) can be modified it doesn’t help. If you could require the root page be cryptographically signed (but by who?) and optionally prompted for updates then we’re talking.