3 ms·
I've been thinking for some time about a mechanism that could be used to assert control over a domain that has a lot of third-party backlinks to it, as in widge
by StuntPope 3y ago
I've been thinking for some time about a mechanism that could be used to assert control over a domain that has a lot of third-party backlinks to it, as in widgets, ad networks, javascript etc.
Because when those domains become defunct or expire, anybody recognizing what they were could grab them and inject malicious code into all the websites with the broken widgets embedded (we've seen this happen with crypto miners, etc)
This kind of a mechanism (along with domainconnect) could work - but it would also need the browsers (perhaps with a plugin?) to verify a domain on embedded components before rendering them.
That would add a lot of DNS lookups though.
Overall a good effort. Would be good to see something along these lines gather some traction.
- elliottinvent 3y agoInteresting idea. If I understand correctly, let’s say a popular CDN was no longer maintained and the domain expired, eg popularcdn.com - you’re looking for a way to use a dns record lookup to verify that the domain (and cdn) is still controlled by who you think it is? I guess for scripts this can be dealt with using integrity hashes but that’s version specific. So this would be a security check at a domain level? I guess the hard part would be that any CDN hijacker could copy the DNS TXT record when they hijack it.
- quickthrower2 3y agoThis can also help to some extent: https://developer.mozilla.org/en-US/docs/Web/Security/Subresource_Integrity https://developer.mozilla.org/en-US/docs/Web/Security/Subres...