5 ms·
I can build a native app from the codebase myself. I can be sure that a native up won't change in-between launches. > In any E2E context you have to trust the
by m1el 7y ago
I can build a native app from the codebase myself. I can be sure that a native up won't change in-between launches.
> In any E2E context you have to trust the client code.
I don't have to trust code which is continuously being delievered from the server. This is an intractable problem.
- _bxg1 7y agoOthers have said it's open-source. Build it yourself, inspect what your browser downloads, hash and compare like normal.
- dependenttypes 7y agoYou can certainly do it, but the rest of the users will stay vulnerable.
- nwsm 7y agoIt doesn't even have to be open-source. Any JS that will get run is handed to your browser and you are able to inspect it.
- gary-kim 7y agoHave fun trying to inspect Javascript code after it has gone through Webpack, Babel or anything else that may have been used for transpiling. Not saying it's impossible but it's still really annoying to do. To add on to that, when there's an update, you usually can't diff it properly because large parts of the transpiled Javascript may change because of a one line change in the actual source code. This is all assuming the website isn't actively trying to make it difficult for you to analyze their code. At least if it's open source, you can inspect the source code then verify that the output is the same.
- vbezhenar 7y agoHow do you hash your browser downloads? Also you need to perform that on every request. It should be possible with additional addons, but definitely not out of the box.
- _bxg1 7y agoYou can easily open the dev tools, view the payloads, and copy them locally. It would be trickier to prevent evaluation before you've done so, but all you have to do is not enter anything sensitive until you've checked