11 ms·
For those who haven't heard of it before, a sentence from the article explaining what it is > With Code Verify, you can confirm that your Instagram Web code ha
by sa-code 3y ago
For those who haven't heard of it before, a sentence from the article explaining what it is
> With Code Verify, you can confirm that your Instagram Web code hasn’t been tampered with or altered, and that your Instagram Web experience is the same as everyone else’s.
- paxys 3y agoIsn't that what HTTPS is for?
- mcosta 3y agoHTTPS guarantee the source, not that meta is sending you the same code as everyone else. With this, an adversary at meta must compromise Meta and Cloudflare.
- ametrau 3y agoI think you would still have big problems if you had an adversary at meta. Bigger than this.
- cookiengineer 3y agoBy that logic the extension from the very same vendor is automatically compromised, too. If a website is compromised, no extension will fix this. Only a rollback to a specific known-to-be-legit hash in IPFS. And meta won't embrace IPFS, ever.
- dboreham 3y agoThe idea is you install the extension ahead of time when you do trust the source.
- cookiengineer 3y agoWhat is the difference to resource integrity and certificate pinning which is already implemented among every single Browser via the HSTS policies? Also, do you really think meta's products will have static assets for eternity from the point of installing an extension? Absurdly unlikely.