3 ms·
Sensitive data is not restricted to logins. If you are pulling in third party JS like for analytics, tracking, social, whatever then that is an attack vector. M
by throwawaymoddle 4y ago
Sensitive data is not restricted to logins. If you are pulling in third party JS like for analytics, tracking, social, whatever then that is an attack vector. Marketing and business teams aren't responsible for security but they have the muscle to pull in dangerous code to the frontend that can be swapped out. It is naive to think that the API is the only thing to focus on.
- hsbauauvhabzb 4y agoThe likelihood of a vulnerability in serverside logic is far higher and more impactful than a large marketing player like google analytics stealing PII.