3 ms·
There is a publisher selected expiration date as part of the signed exchange which the client inspects. The expiration also cannot be set to more than 7 days in
by gregable 6y ago
There is a publisher selected expiration date as part of the signed exchange which the client inspects. The expiration also cannot be set to more than 7 days in the future on creation. This minimizes, but of course does not eliminate, this risk.
- xg15 6y agoIt also makes signed exchanges completely unusable for delivering packages offline. (E.g. the USB stick scenario) What a bummer.
- smichel17 6y agoBrowsers could have a setting to optionally display the content anyway, along with a warning to the effect of "site X is trying to show an archive of site Y", similar to how we currently handle expired or self-signed SSL certificates.