logoalt Hacker News

dborehamyesterday at 6:05 PM1 replyview on HN

There are already tools and techniques to validate served JS is as-intended, and these techniques could be beefed up by adding browser checks. I've been surprised these haven't been widely adopted given the spate of recent JS-poisoning attacks.


Replies

bawolffyesterday at 11:32 PM

You mean like SRI? That's not really what happened here, so its not really relavent.