Hacker News new | ask | show | jobs
by zobzu 4659 days ago
it adds not much. it does make it more complex to intercept because you need to serve diff js. il also means cleartext isnt on the server at all til compromised.

but yeah the design is bypassable. thus not really safe. clients should do it natively i guess.