3 ms·
Well, this also allows powerful actors to inject malicious code into your page. I think they can easily be forced via an NSL to target certain websites or clien
by kirab 12y ago
Well, this also allows powerful actors to inject malicious code into your page. I think they can easily be forced via an NSL to target certain websites or client IPs.
- jlebar 12y agoThis a thousand times. I'm not accusing these guys of being dishonest, but we know that the three-letter organizations do this sort of thing, both with and without the knowledge of web hosts. It seems like these guys (and anyone else who has a similar service) shouldn't require people to trust them. Instead, they should allow CORS (it appears cdnjs does) and provide boilerplate code that verifies the script's sha256 before inserting it into the page.