Hacker News new | ask | show | jobs
Exfiltrating User’s Private Data Using Google Analytics to Bypass CSP (medium.com)
3 points by amirshk80 2192 days ago
1 comments

tl;dr; Since a lot of websites allow google-analytics.com, 3rd party javascript code can use the fact there is no verification on the UA-ID to exfiltrate information.