Skip to content

Provenance vs. content #52

@mozfreddyb

Description

@mozfreddyb

I know the spec text already touches on this, but we would like to provide an additional piece of concern.

Hashed content provides a direct connection between the author of the HTML and the expected resource. Regardless of the author and the serving infrastructure.

Provenance only provides a connection to an opaque holder of a private key.
While key is intended as a countersignature from the author of the resource, it might as well be held by the CDN itself.

In essence, the provenance guarantee is completely opaque to the user, the website and the browser.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions