[Bug 20789] "digest" (cryptographic hash) attribute for <script>

https://www.w3.org/Bugs/Public/show_bug.cgi?id=20789

--- Comment #15 from Victor Costan <costan@gmail.com> ---
@Robin: I disagree that Web application authors have to trust the CDNs. If the
CDN is down, there are ways to fall back to a resource on the author's server,
using JavaScript. I hope that we'll eventually have a general method for doing
that in HTML, perhaps along the lines of srcset. It would be nice to have the
same failure mode if the CDN is compromised and starts serving content that
differs from what authors intend it to serve.

Thank you very much for the advice of approaching browser vendors. I will make
one more pass over the specification and then I will start doing that. I would
appreciate any feedback w.r.t. unresolved issues in the specification,
especially if it comes before I start trying to implement it :)

-- 
You are receiving this mail because:
You are the QA Contact for the bug.

Received on Friday, 22 February 2013 19:45:23 UTC