#SkyPack

๐Ÿงฟ๐Ÿชฌ๐Ÿ„๐ŸŒˆ๐ŸŽฎ๐Ÿ’ป๐Ÿšฒ๐Ÿฅ“๐ŸŽƒ๐Ÿ’€๐Ÿด๐Ÿ›ป๐Ÿ‡บ๐Ÿ‡ธschizanon
2024-11-09
2021-02-04

Finally found the time to open a discussion on the Snowpack forums about the lack of subresource integrity (SRI) in Skypack: github.com/snowpackjs/snowpack

(Background: my post from the end of last year titled Skypack: backdoor as a Service? ar.al/2020/12/30/skypack-backd)

#skypack #snowpack #SubresourceIntegrity #SRI #security #privacy

2020-12-31

โ€œIf I were In-Q-Tel right now, Iโ€™d be drooling as I wrote a check with lots of zeros in it for the Skypack folks because widespread use of Skypack would be any national security agencyโ€™s wet dream. Imagine being able to inject any code into any web application at any time to obtain login credentials, etc.

This isnโ€™t even a backdoor. This is a wide open frontdoor. Itโ€™s basically Backdoor as a Service.โ€

ar.al/2020/12/30/skypack-backd

#skypack #snowpack #cdn #security #privacy

Silhouette of door, ajar, with light spilling into a dark room (black she white illustration)

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst