Hacker News new | ask | show | jobs
by jquery 932 days ago
Please make a new API key folks. There's a lot of tricks to scrape a text box and watching the network tab isn't enough for safety.
1 comments

Who could scrape the text box in this scenario?
Good luck spotting it if it's attached to the window.onclose event. Chrome extensions could save it to storage. Probably even some chrome vulnerabilities (it would just be a devtools network tab bypass so not technically a 0-day). And that's just top of mind, I'm sure there's other methods.
Chrome extension malware.