Hacker News new | ask | show | jobs
by jeroenhd 2115 days ago
Is there anything in the web bundle standard that forces outdated pages to be refreshed? The spec seems to say little more than "detecting stolen keys is not our problem".

I can imagine this being a problem when news stories turn out to be false alarm and Google happily keeps serving the original content instead of the corrected content.

There's also a risk of vulnerability here, as getting a signed package might very well be used to host phishing pages on web caches.