4 ms·
> What if there was a mechanism for signing a webpage? > This could easily be promoted as a safety feature, you only run the code the web server gives you, not
by Volker_W 5y ago
> What if there was a mechanism for signing a webpage?
> This could easily be promoted as a safety feature, you only run the code the web server gives you, not something that has been exposed to a man in the middle attack several times over.
This already exists, it is called https. The s in https stands for security, i.e. encryption and signing.
> The browser could be told not to render anything is the signature does not match the content.
The problem with this statement is that adblockers are part of "The browser". So the browser/the adblocker coud still choose to render something with no signature.
Also, what does "rendering" mean? An adblocker changes what "rendering" means:
For example, if the html includes the line
<img src="https://www.qries.com/images/banner_logo.png https://www.qries.com/images/banner_logo.png" alt="Qries" width="200" height="90">
then the browser will usually request banner_logo.png and show that here. But the browser could also choose not to do that. If qries.com would be in the blocklist of your adblocker, your browser would choose not to send that request and not to show that image.
- ThinkBeat 5y agoHttps is transport integrity. If you download malware, https ensures that it gets to you in one piece. (or anything else you wish to receive) What I meant is that once the content has been delivered to the browser, it will not be displayed unless the integrity of the payload is ensured. A dumb example, because I am not creative tonight. You download a book, Neuromancer by Gibson. The book is stored in an encrypted zip file. The zip file is delivered to you via https. You can't read the book unless you know what the key is. If the zip file has been altered post download, it probably will not open even if you know the correct key. On the web one could argue that if such a mechanism was possible, then it would "protect" people. Let's say Bob is doing his weekly online banking and crypto investing. Bob isn't that good with computers. Malware is everywhere, maybe someone has been able to sneak an extension into Bobs Chrome browser and it modified the content so he transfers his crypto to the extension authors account. If the page was unable to be displayed less its integrity was ensured this would save Bob money. Yes I agree that as the web exist today with an unholy smear of html,css, JavaScript, Pictures, links, cookies etc it would be difficult to do. But we can go beyond what we have now. Imagine if someone has slid a nefarious extension into your browser. it can change anything it wants as things sit now. T
- Volker_W 5y agoThis does not work if the one who wants to change a site controls the browser.