3 ms·
(Feel free to drop me an email - silverlock@cloudflare.com - if you want to chat more) We’re iterating on a standard for this - our current thinking is to use
by elithrar 5y ago
(Feel free to drop me an email - silverlock@cloudflare.com - if you want to chat more)
We’re iterating on a standard for this - our current thinking is to use well-known URIs to publish both a public key (is the hash legit?) and hash endpoint URIs for clients to pull.
The extension requirement is an “unfortunate” friction point due to needing a separate security context for hash verification. Doing this part natively will be the biggest adoption win.