Hacker News new | ask | show | jobs
by callahad 3541 days ago
Once AMP stabilizes, I'm hoping Google will encourage the use SRI to ensure that the content is what a site expects: https://developer.mozilla.org/en-US/docs/Web/Security/Subres...
1 comments

Still unacceptable as it would still cause my users to expose their IP address to someone else's server.
Unfortunately the ubiquity of FB and G+ buttons, Google analytics and CDN use has raised a generation of web developers who don't see that as a problem.
Certificate Transparency will reveal the domains you connect to over TLS to a Google server anyway. Assuming you don't already use Google's DNS, that is.
Google could and should change their requirement to be that the integrity value for the script must be in their approved list rather than requiring their path.