Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I might be alone here - but I would never use a CDN that isn't back by a company with a strong vested interest in preventing security breaches of their servers.

Consider that the community CDN is compromised - if that file gets replaced with a different JS file, you've now provided an attacker an XSS hole into _every_ page using the CDN.

I have a reasonable trust in Google to secure their own servers against such a compromising attack, but have no similar reason to put faith in smaller companies/services.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: