3 ms·
I continue to wait for a compromise pointing to a cdn, cloud provider, or some other shared component like a JavaScript library that underpins the modern intern
by gpapilion 3y ago
I continue to wait for a compromise pointing to a cdn, cloud provider, or some other shared component like a JavaScript library that underpins the modern internet. This does not appear to be it according to the article. Something like an analytics service could really cause wide impacts.
Seems like this is a compilation of other breaches.
- jauntywundrkind 3y agoThere is a technical fix, Sub resource Integrity, that . makes sure your app is getting the download it expects. Adoption is probably pretty minimal though. https://developer.mozilla.org/en-US/docs/Web/Security/Subresource_Integrity https://developer.mozilla.org/en-US/docs/Web/Security/Subres... I think the big thing making this unlikely though is that very few folks use cdns these days. We designed ESM as a module system for the language, but then took a good fraction of a decade to build import-maps, to let us actually use modules in a modular way. Good news, we can finally use modules modularly! https://caniuse.com/import-maps https://caniuse.com/import-maps Bad news? Oh import-maps only works for the simplest case. Doesn't work in webworkers/service workers. https://github.com/WICG/import-maps/issues/2 https://github.com/WICG/import-maps/issues/2 The point is that single page apps almost always are bundled together, as using CDNs hasn't even been technically possible. Also, CDNs are kind of somewhat pointless, now that http caches are partitioned by origin (for security reasons). They might have better anycast infrastructure to get the content out faster, but without the caching there's no inherent advantage. The user will download the same jquery file again in each site they go to, no already having it cached anymore. Bah humbug!