> The system described in this post doesn’t scale to arbitrary assets – yet – but we are exploring ways in which we could extend this offering for something more general and usable like Binary Transparency.
It would be great if other makers of E2EE apps (like ProtonMail and Matrix's Element) joined this initiative and made the verifier work for their web apps too. I'm sure Cloudflare would be happy to partner with those organisations.
For context, there have been a few other attempts in the past to verify the contents of web apps, such as Signed Pages[0] and SecureBookmarks[1], but those have had usability drawbacks. One thing I hope Cloudflare end up supporting is returning the version/hash info from a verifiable append-only log. That way, users can choose to run an old version of a web app until the new version has been around for long enough to be independently reviewed.