| Looking at the image on the link, the "checksums" are a suspicious 32 characters... Hoping you guys are not using md5sums. Am I missing something, or would this let any node (supernode/browser) in the system potentially replace arbitrary content with their own content? [1] Hopefully JS isn't being served by this mechanism (attack vector pretty obvious there), but even images are still a concern [2] [3]. [1] https://en.wikipedia.org/wiki/Collision_attack#Chosen-prefix... [2] https://threatpost.com/apple-patches-ios-flaw-exploitable-by... [3] https://imagetragick.com/ |