Hacker News new | ask | show | jobs
by mschoebel 3539 days ago
Still unacceptable as it would still cause my users to expose their IP address to someone else's server.
2 comments

Unfortunately the ubiquity of FB and G+ buttons, Google analytics and CDN use has raised a generation of web developers who don't see that as a problem.
Certificate Transparency will reveal the domains you connect to over TLS to a Google server anyway. Assuming you don't already use Google's DNS, that is.
Google could and should change their requirement to be that the integrity value for the script must be in their approved list rather than requiring their path.