-
Notifications
You must be signed in to change notification settings - Fork 8
Open
Description
I know the spec text already touches on this, but we would like to provide an additional piece of concern.
Hashed content provides a direct connection between the author of the HTML and the expected resource. Regardless of the author and the serving infrastructure.
Provenance only provides a connection to an opaque holder of a private key.
While key is intended as a countersignature from the author of the resource, it might as well be held by the CDN itself.
In essence, the provenance guarantee is completely opaque to the user, the website and the browser.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels