Remove tag anonymization
article thumbnail

Subresource Integrity and Upgrade-Insecure-Requests are Now Supported in Microsoft Edge

Troy Hunt

Because especially when it comes to security, there are fundamental and inherent shortcomings in everything from HTTP to HTML and many of the other acronyms that make the web work as it does today. Edge now joins the other major browsers in rejecting any script which doesn't hash down to the value specified in the integrity tag.

IT 49
article thumbnail

The JavaScript Supply Chain Paradox: SRI, CSP and Trust in Third Party Libraries

Troy Hunt

This tag was in the source code over at secure.donaldjtrump.com/donate-homepage yet it was pulling script directly off Igor Escobar's GitHub repository for the project. I know, we're all shocked but bear with me because it's an important part of the narrative of this post. Until now. It was the US Courts too.