3 ms·
I wonder how the Subresource Integrity can expand to the root document hash (other than using IPFS gateways). UPD yeah, extension hashing resources sounds nice
by wizzard0 4y ago
I wonder how the Subresource Integrity can expand to the root document hash (other than using IPFS gateways).
UPD yeah, extension hashing resources sounds nice too
- holmesworcester 4y agoI've wanted this too! You could include subresource integrity hash in the URL that the browser will check against the page. This would make things like Cryptpad and Skiff, or group invite links in Signal, way more secure.
- blintz 4y agoThis seems like it would be a cool browser standard. The browser could check that the specified SRI hash matches one published by some other entity, and then include extra information in the ‘lock’ icon or dialog, that goes further than TLS. Usually, when I have an idea for a standard, it turns out one exists, so maybe I’ll do some digging…