|
|
|
|
|
by dasony
5045 days ago
|
|
The idea is that users wouldn't have to download the same jquery or whatever script over and over for every site they visit. It makes less sense when it comes to not-so-popular script files, but I guess there's a convenience factor too. |
|
Or at the very least, we need some way to say "get this script from this URL, but only if it hashes to <this value>, since otherwise it's been compromised". Why worry about CDNs when you can design the script-switcheroo attack right out the system in the first place?
I wrote about this in June: http://rachelbythebay.com/w/2012/06/27/src/