18 ms·
I wish there was a bigger push for integrity checking in the browser. It would be foundational to any solution that fixes that problem. There is already integ
by Zamicol 4y ago
I wish there was a bigger push for integrity checking in the browser. It would be foundational to any solution that fixes that problem.
There is already integrity checking for subresources: https://developer.mozilla.org/en-US/docs/Web/Security/Subresource_Integrity https://developer.mozilla.org/en-US/docs/Web/Security/Subres...
Newcastle University had a proposal for website wide integrity checking:
https://github.com/toreini/DOMtegrity https://github.com/toreini/DOMtegrity
Note that only 7 people have starred it on Github.
- roywiggins 4y agoI don't think either of those help if the website itself is pwned? SRI is fine if your website is secure but the CDN is pwned, the other one seems to be a defense a website can use against a malicious extension, but the risk with LastPass is if the LastPass website is pwned it can just read your password. You'd need some way to transfer essentially signed app bundles to the browser for the browser to verify, which seems like a different sort of project.
- bigDinosaur 4y agoI assume ultimately something like signed releases will become a thing on the web, with the signing process being separate from the other processes so that a hack has to compromise two entirely different systems, not just the build pipeline, to allow new JS to run. Currently the only thing that is signed is the SSL certificate which of course guarantees precisely nothing about the actual website content served from the server other than that someone didn't tamper with it after it was sent.
- adgjlsfhk1 4y agoWho hosts the signature? If you've hacked someones server enough to push out new JS what's to stop you from signing it?
- lxgr 4y agoHow would you approve updates to any site content in this model? Have users approve every time any embedded JavaScript hash changes?