3 ms·
Did you even bother to read the article before commenting? There is nothing a client can do when the server is compromised.
by premium-concern 10y ago
Did you even bother to read the article before commenting?
There is nothing a client can do when the server is compromised.
- edejong 10y agoActually, yes, I did read the article. When I read 'Javascript malware', I understand this to be ECMAScript which is executing on the clients machine but delivered by the origin site. The ECMAscript has access to the keyboard while the window has focus, so could do a MITM. Like I said, there are various ways to prevent this from happening: 1. Instruct users never to enter card details directly into a website, but rely on a redirect to the card provider. This would change the origin. When properly setup, this should catch 99% of the problems. 2. Provide stricter browser controls, so third-party ECMAscript is not loaded into the browser by CORS. Again, instruct the user or have us make better browsers. 3. Lobby for better payment services. Here in the Netherlands, payment is done using iDEAL, on a separate origin (using redirects) and the payment is validated using a separate device. The secondary problem is with the websites, the primary problem is with the supporting technology.