3 ms·
Thanks. I'd use a browser extension, and also constrain what gets sent to the server. If the server was really compromised, it could just copy the CC# into ano
by danielharan 13y ago
Thanks. I'd use a browser extension, and also constrain what gets sent to the server.
If the server was really compromised, it could just copy the CC# into another field in the form (so it gets sent twice, encrypted and unencrypted) - and the server would get the data without having to change the JS. Integrity checks would not turn anything up. A properly paranoid browser extension should have a specified format for sending a form, so that no extra information is leaked.
In my case it's bids rather than CC#s, though the same pattern holds of encrypting with the tender creator's public key.