Hacker News new | ask | show | jobs
by Buge 4367 days ago
Yeah I think you're right.

And if all authentication is done client-side with javascript, the attacker could steal your private key and use it to attack other sites.