-
If you have a proper Content Security Policy (developers.google.com/web/fundamentals/security/csp/), your users are safe. If you don’t, this article by @D__Gilbertson gives you an idea of what might happen. (via @yoavweiss, @ericlaw) hackernoon.com/im-harvesting-credit-card-numbers-and-passwords-from-your-site-here-s-how-9a8cb347c5b5
-
@tomayac @D__Gilbertson @yoavweiss @ericlaw Important addition: x.com/__agwa/status/949757988566216705