Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Wouldn't you be able to deploy an app script website, which is hosted on "script.google.com" and make use of this?


your code do not run from that domain at all.


it does if I hack your dns server :)


It seems most if not all google domains are HSTS preloaded so no you can't: https://hstspreload.org/?domain=script.google.com


Does Chrome do certificate pinning checking in this case?


No it does not. Firefox does by default. But then again, you would need the user to install your cert. Good luck with that




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: