4 ms·
These concepts are interesting: https://codegolf.stackexchange.com/questions/18217/javascript-load-and-sha-256 https://codegolf.stackexchange.com/questions/182
by jrruethe 8y ago
These concepts are interesting:
https://codegolf.stackexchange.com/questions/18217/javascript-load-and-sha-256 https://codegolf.stackexchange.com/questions/18217/javascrip...
https://bitbucket.org/geraintluff/caution.js/ https://bitbucket.org/geraintluff/caution.js/
The idea is that a long data-uri containing hashes and a small loader function are bookmarked. The loader won't load the corresponding javascript unless the hashes match. The user only needs to verify the javascript once, then they can rely on their bookmark containing the hashes. If the server were to swap out the javascript, the bookmark would fail to load it.
- Sir_Cmpwn 8y agoOooh, that's very cool. Thanks for the links.
- SahAssar 8y agoIsn't that just SRI in a bookmarklet? With SRI you give the browser a hash and if the resource does not match it does not load.
- Something1234 8y agoDoesn't SRI require the hashes to be in the __loaded__ html? I believe parent is referring to a page which is the same, but has been compromised on the server side, meaning you can't trust the html, even if the server is who it says it is.
- SahAssar 8y agoRight, but what I'm saying is that you don't need the loader. Just have a bookmarklet with html that contains script tags with SRI. The loader is just another step you need to trust.
- dividuum 8y agoThat does indeed work. Pretty neat. For anyone trying, here is basically all you need: data:text/html,<script crossorigin="anonymous" integrity="..." src="..."> In total that should be a lot smaller than the linked codegolf answer.
- hahahihi 8y agoif you send the datauri by email (webmail) and use it from there someone with phisical access to the computer wont be able to change it easily.
- xyzzy123 8y agoYou might also like substack’s work on hyperboot.