4 ms·
It would be even cooler if this were done by comparing a hash of the library's remote and local copy, so it could be on any server and not bound to the same dom
by bk 18y ago
It would be even cooler if this were done by comparing a hash of the library's remote and local copy, so it could be on any server and not bound to the same domain.
- patio11 18y agoI hope it is a cryptographically secure hash that STAYS cryptographically secure. Otherwise ten years down the road someone will figure out a way to force collisions and then, bam, you'll be running l33tcrew.ru's copy of Prototype with the access privileges of bankofamerica.com . No problem fixing that one, all you have to do is roll out a patch to every standards-compliant browser in the world, oh, yesterday would have been good.
- iigs 18y agoOr specify the hash type you'd like to see at the point you invoke the script. It can't retroactively protect pages that were published with the insecure hash, but it certainly would allow the author to update their site upon awareness of a hash vulnerability.