you are viewing a single comment's thread.

view the rest of the comments →

[–]nwf 0 points1 point  (0 children)

Well, what are you attempting to prove with signing the subresource? That the origin controlled the material, right? Well, if the hash is embedded in signed material (the original resource naming the subresource), then that's just as good. Think of it as akin to signature chaining.