3 ms·
I don't know what industries you've been working in but in any sensitive business third-party javascripts are under the same tight controls as any other code, a
by Puts 5y ago
I don't know what industries you've been working in but in any sensitive business third-party javascripts are under the same tight controls as any other code, and changes in javascripts are going through the same change management controls as any other code before entering production.
Even Google have had issues with malware being distributed via adsense:
https://www.businessinsider.com/google-has-shut-down-a-malicious-ad-attack-on-its-adsense-network-2016-11?r=US&IR=T https://www.businessinsider.com/google-has-shut-down-a-malic...
Not to speak of the Megacart hacks:
https://www.riskiq.com/blog/external-threat-management/magecart-british-airways-breach/ https://www.riskiq.com/blog/external-threat-management/magec...
- dec0dedab0de 5y agoYou can't put third party javascript through change management. Unless you download and host it yourself, in which case it's not really third party.
- Puts 5y agoWell we can absolutely talk semantics. Code written by a third-party is third-party code however it is hosted. Your conclusion is right however. If you are serious with your security and change management you host all scripts yourself. Or use sub-source integrity: https://developer.mozilla.org/en-US/docs/Web/Security/Subresource_Integrity https://developer.mozilla.org/en-US/docs/Web/Security/Subres...
- dec0dedab0de 5y agoOf course it's third party code. I meant that it's not really third party in the context of this article advocating for a same origin policy for javascript. I only came across SRI while dealing with CSP, and I didn't quite understand why anyone would subject themselves to that until just now. Thanks for pointing it out.