4 ms·
But this is being run by a party you trust with that data in the first place surely? It's capturing the things you are typing into the website's input boxes!
by PJDK 9y ago
But this is being run by a party you trust with that data in the first place surely?
It's capturing the things you are typing into the website's input boxes!
- krangu 9y agoJust because you trust the first party site with that information doesn't mean you would necessarily trust a third party to store or transmit that info.
- orwin 9y agoWe trust the website we give our information to. It is https-based (else my browser will tell me) and probably using an ORM that will 99% of the time hash my password. But the javascript layer... Sorry, call me paranoiac, but i will never trust the javascript of a website. With no webdev experience, i was able to inject js (almost by mistake) three years ago. Moreover, is the js communicating with the backend using https too? How can i check that? Are those js library on the website server, or are they hosted by a third party? I can trust them, but how do i know that no attacker was able to modify those scripts? Yes, those risks are small, but i'd rather have ublock making those risks closer tho 0 than not, am i wrong?