4 ms·
This reminds me of the time I caught my mortgage lender using javascript loaded directly from a github repo on their mortgage application process. I reported it
by jmvoodoo 6y ago
This reminds me of the time I caught my mortgage lender using javascript loaded directly from a github repo on their mortgage application process. I reported it to them and they didn't understand the problem.
- vmception 6y agothat's pretty funny but what is the problem with that? direct link, possibility of updating, same possibility of 404 as anything else, CDN and caching included
- khalilravanna 6y agoIf it’s straight up linking a non-versioned file (e.g. live file) it implies the owner of that Github repo has direct access to update and run code in client’s browsers. Could start shooting off API requests dumping the contents of cookies/localStorage, set up keylogging, etc. IMO seems like a pretty big security hole.