|
|
|
|
|
by Dyaz17
2552 days ago
|
|
Hey HN! I created GuardScript because in my previous company we started to include more and more third-party Javascript from SaaS services on our homepage, and this created security risks for us [1] [2]. In order to reassure us, a few of these companies created independently what is essentially GuardScript: a service that monitors every few minutes any changes made to your Javascript files and sends you a notification with the changes made. You can then detect any malicious modification by analyzing these results.I decided to build it for a broader audience. I'd love feedback and suggestions on how to make it better. Thanks! [1] https://www.theregister.co.uk/2018/09/12/feedify_magecart_ja
[2] https://www.zdnet.com/article/hackers-breach-statcounter-to-... |
|
I'd want a runbook feature so that anyone getting the email has a procedure to:
* check release notes to identify a false alarm
* if not identify which source files the URL is used in
* disable those URLs
* flush caches
* confirm they're disabled
* contact the service provider
* roll back when upstream is fixed
Or something like that. Man, I do not miss ops work.