Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

For content that is already public but needs to be protected from modification like images and scripts couldn't it be hashed and the hash just sent with the page your viewing. Then the browser could download extra assets from an insecure source like a proxy or cdn and know that it hasn't been modified?


So then the browsers have to implement two security systems.


Not entirely, as SSL already includes a hash. That said, I don't agree with doing it.

However, I do believe that we should investigate ways of authenticating larger downloads automatically.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: