Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

At any time any analytics package or update can just read whats stored client side and send it to Facebooks servers.

Is everyone intentionally ignoring this or actually unaware?

Things stored in plain text client side, can be read in plain text client side and resyndicated.

All this focus on the first transmission being encrypted while in flight and server side is just a bit negligent.

Its a system ripe for abuse and thats it.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: