Can the boundary nodes ever be decentralised and still guarantee a secure frontend?

As I understand it certified assets work by the boundary nodes installing a service worker that verifies the certification header on all http responses.

How would a rogue boundary node be prevented from not installing this service worker and then giving you a fake NNS frontend that transfers out all your ICP as soon as you have logged in with Internet Identity?

1 Like