Hacker News new | ask | show | jobs
by convolvatron 61 days ago
yes, but what's to stop a malicious actor from intercepting a signature request and replacing its own contents in place of the legitimate one. yes you would find out when your push was rejected, but that would be a bit late.