Hacker News new | ask | show | jobs
by chubs 1262 days ago
Someone please correct me if i'm wrong... but there was a kerfuffle in 2017 about Circle using third-party JS which could be an attack vector: https://news.ycombinator.com/item?id=15442636

To give credence to this, a gitlabber spoke up in that thread, said it was a serious thing and they deliberately had no third-party stuff on their site for that reason.

And I just logged into Circle today, and use the Safari network inspector to see what JS it loads... and it's still plenty of third party stuff that I can see:

* Amplitude * Segment * cci-growth-utils * Statuspage * DataDog * HotJar * Pusher

Not sure if this is an issue, but it doesn't make me comfortable.