3 ms·
Why would you have to verify the JavaScript every session? If you are transporting over HTTPS and have a Content Security Policy (https://developer.mozilla.org
by ContentSP321 5y ago
Why would you have to verify the JavaScript every session?
If you are transporting over HTTPS and have a Content Security Policy (https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP) it seems like that job is largely taken care of.
- maqp 5y agoI'm not talking about XSS vulnerabilities, but having to trust the vendor to do the right thing every time I use it. Some companies can be coerced, internally compromised, and TLS and X.509 isn't exactly designed to be safe against nation state attackers so MITM can inject malicious JS clients. Native clients suffer from code distribution problems too, but to much lesser extent, especially with reproducible builds and actually readable code as opposed to minified JS.