Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

He'd also need to HTTPS all the scripts that script requires, and devise some way to ensure that the script was never called from a page that itself included any HTML or JS over a non-HTTPS connection, because any of those document loads could also MITM the script. Isn't Javascript crypto fun!


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: