Subresource Integrity Sample
googlechrome.github.io
googlechrome.github.io
If it's 3rd-party resources, wouldn't this make things like Google Analytics unable to be updated if they use hashes? I guess this must be mostly targeted at resource hosts who modify resources maliciously, but how often does that occur?
If it's 1st-party resources, wouldn't SSL better handle the authenticity part? If they can modify resources you're loading but hashing, surely they can modify the resource delivering those.
There have been proposals for adding fallback URLs to fetch from if the primary resource fails. This way you can have your CDN and cache but fallback to a local resource too. As the spec is written currently it looks like the user will have to do this manually with an on error event. I haven't been following closely enough to see why it's taken this route. Perhaps for simplicity of the initial implementation?
Hopefully not. Even if we ignore the possibility of hash collisions (since that's not that likely yet with SHA 256).. There's still the issue of cross origin data leakage. Using a known hash and whether a request is made for the resource to tell if a user has visited another website.
This should require a cors header
(Legitimate) Site A sends file a.com/image.png w/ a hash.
(Attacker) Site B sends file b.com/image.png w/ identical hash. If no request is made for b.com/image.png, the attacker knows the visitor has gone to Site A.
Another benefit of identify resources by their hash is that we don't need to request them from a specific host. Instead, you can get them from any CDN that has a matching resource.