Hacker News new | ask | show | jobs
by than3 1257 days ago
I've found that companies where they've done this (hotlinked) often have incompetent or overburdened people, and this shaming wouldn't even register.

Hotlinking code like that though is just plain stupid from the liability perspective. If they are a business, they should be worried about 3rd-party liability.

The fact that they are doing this makes the website hosting the script, a nice juicy target for watering hole/supply chain attacks.

What are they going to do if that happens? Its not like business insurance will cover that.