Re: [w3c/ServiceWorker] Is it possible to serve service workers from CDN/remote origin? (#940)

The XSS attacker can compute the hash of the resource hosted off-domain, so the hash gives no extra defense. 



-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/w3c/ServiceWorker/issues/940#issuecomment-280935016

Received on Sunday, 19 February 2017 17:46:49 UTC