Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Great! Now if only we can get asymmetric document signing going, including a "must be signed" header to compliment HSTS...

SRI does little for trust when your CDN is also proxy-caching your HTML (e.g. Cloudflare).



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: