Lukas Weichselbaum @webappsec.dev · Nov 18

Signature-based SRI is being spec'd right now: wicg.github.io/signature-ba... This will be useful for many use case and become relevant for PCIv4 compliance which requires assuring the integrity of sourced scripts (6.4.3). Please chime in and share your use cases: github.com/WICG/signatu...

14 likes 4 replies

?

Replies

Javan Rasokat · Nov 18

Looks like PCI is a real innovation enabler. I was astound when I saw the requirements of CSP, too. Now this.

Ben Stock · Nov 18

On the plus side, one of the limitations of SRI was third parties adding random content (see swag.cispa.saarland/papers/steff... final table). However, SRI in its current form protects including sites from a full compromise, whereas this assumption is being relaxed if there are signatures involved.

Lukas Weichselbaum · Nov 18

also please join me in thanking @mikewe.st, @ddworken.bsky.social and @yoav.ws for pushing this forward!

Lukas Weichselbaum · Nov 18

cc: @scotthelme.bsky.social reporting is being worked on as well