Unfortunately you just need to hack keybase and serve malicious code. It doesnt matter if its signed if my malicious code tells you the signature verification succeeded.
Client side needs versioned code to make this harder. Including signed, versioned javascript code, automagically.
This will also make alterations of web sites code a lot easier to detect.
Client side needs versioned code to make this harder. Including signed, versioned javascript code, automagically.
This will also make alterations of web sites code a lot easier to detect.