Slacker News Slacker News logo featuring a lazy sloth with a folded newspaper hat
  • top
  • new
  • show
  • ask
  • jobs
Library
← Back to context

Comment by ronnier

3 hours ago

Yeah if an attacker was able to insert javascript then it's possible.

2 comments

ronnier

Reply

blr_lpm  3 hours ago

For this particular threat vector, where the client is compromised, the backend doesn’t matter.

  • franga2000  43 minutes ago

    A compromised server can inject exfil code into the web page it serves. If you only ever use the apps then you should be fine though.

Slacker News

Product

  • API Reference
  • Hacker News RSS
  • Source on GitHub

Community

  • Support Ukraine
  • Equal Justice Initiative
  • GiveWell Charities