4 ms·
I'm in the middle of developing killginx, which will perform some of these attacks, so I'll just link them here when I'm done. You're definitely wrong about Str
by dfv 6y ago
I'm in the middle of developing killginx, which will perform some of these attacks, so I'll just link them here when I'm done. You're definitely wrong about Stripe being invulnerable to this sort of thing, and half wrong about the other things. Up-to-date Firefox and Chrome are not the only things that autofill or negotiate http connections.
- viraptor 6y ago> Up-to-date Firefox and Chrome are not the only things that autofill or negotiate http connections. Sure. But it basically means it's a matter of time before everything else stops doing it too. I've just tried to use the stripe checkout js from an HTTP site and it doesn't work. You can send your own requests of course, so I wonder if that's what you meant instead... (To be clear, I didn't say stripe is not vulnerable, just that you can't use their scripts as they are now - so simple id swapping wouldn't work) Either way, I'm curious to see killginx.
- olliej 6y agoLoading javascript from another domain is deliberately not observable, so for it to have vulnerabilities stripe would have to be putting user data in javascript responses, which seems unlikely. Given the article is deleted I don't know what points the author was making, but if you have found a way to convince stripe (or anyone else) to transmit user data in scripts you should probably report that. I don't know if they have a bug bounty program.