|
|
|
|
|
by Ajedi32
2390 days ago
|
|
> one may manage to upload an html file to the bank's server and serve a -signed- page that google amp will cache Only if you have the bank's private key, and the ability to serve arbitrary content from the bank's domain. In which case... yeah, I don't see how the signed exchanges standard makes that problem significantly worse. |
|
Nobody benefits from this shit than google. Do we really need more attack surfaces?