3 ms·
Well, couldn't checksum the whole page? I know that creates a big pain in the ass in terms of modifying the page and in terms of making the page dynamic, but b
by methehack 13y ago
Well, couldn't checksum the whole page?
I know that creates a big pain in the ass in terms of modifying the page and in terms of making the page dynamic, but bracketing those two concerns -- why wouldn't that work?
- Wilya 13y agoBecause if I own your server, I can set it up so that it serves the good file to your pingdom-like service, and corrupted files to everyone else. Or more realistically, I'd do something more targeted, like serving the bad files only to the ip block of my business competitors.
- sneak 13y agoYou can checksum the whole page, but any externally loaded JS can monkeypatch any other part. Use analytics? How about a payment widget? All of these can affect every part of the js environment, overwriting anything from jQuery to sjcl. Alternately, they could leave the crypto alone and just hook into keystroke handlers or the DOM and steal your plaintext that way. Also, some browsers will run JS from urls referenced in img tags as long as they are served with a text/javascript MIME type. It's far too big an attack surface.