4 ms·
Though I'd never do such a thing, your point is completely valid.
by redment 14y ago
Though I'd never do such a thing, your point is completely valid.
- samwillis 14y agoAnd I would always lean to the side of trust in people, I wouldn't expect you or most people here to abuse it. Its a little bit of a pet hate, the suggested linking to JavaScript files in another persons repository. The worst was the HTML5 Shim, for a long time they suggested linking directly to their svn repo, fortunately they don't now. It was about the same time people started thinking about using the google cdn for javascript libraries and so people just did it thinking they were helping their page load times when in fact they were compromising the security of their users and themselves.
- samwillis 14y agoJust thinking about this, what's needed is some kind of trusted public cdn that you can send files to but cannot change so that library writers can point towards a cdn hosted version of the library without running one themselves and removing security vulnerability.
- simonbrown 14y agoOr a hash attribute to file and script tags. Of course, either case would mean redment wouldn't be able to update it.
- simonbrown 14y agoUsing Google CDN places no more trust in Google than using Google Analytics or AdSense. Unless your site handled sensitive data or is mission critical, I believe it's reasonable to trust Google not to do anything malicious. It's worth noting that the same issue exists with Chrome extensions. I wonder how strong a Google password the authors of popular Chrome extensions have.