Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
throwawaymoddle
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
throwawaymoddle
4y ago
Sensitive data is not restricted to logins. If you are pulling in third party JS like for analytics, tracking, social, whatever then that is an attack vector. Marketing and business teams aren't responsible for security but they have t
2.
▲
by
throwawaymoddle
4y ago
> Only the API needs to be secure. If users type passwords, sensitive data, anything into the frontend then any javascript, plugins etc pulled in by that page is an attack vector.