Free Republic
Browse · Search
General/Chat
Topics · Post Article

To: Tunehead54
Good tip. Thanks - if you click on anything you really don't know what you're authorizing.

Unfortunately, it doesn’t help because these vulnerabilities don’t require the user to do anything except navigate to a website that has a script that will infect your browser by invoking browser services maliciously. . . Or it could be on a user’s frequently used website and the script comes in on a rotation advertisement from Google. No authorization required.

20 posted on 02/25/2019 3:40:04 PM PST by Swordmaker (My pistol self-identifies as an iPad, so you must accept it in gun-free zones, you hoplaphobe bigot!)
[ Post Reply | Private Reply | To 13 | View Replies ]


To: Swordmaker

“Or it could be on a user’s frequently used website and the script comes in on a rotation advertisement from Google. No authorization required.”

This is a HUGE problem most don’t realize is happening. They blame the site but it’s actually the ad API. The Google ad API is DANGEROUS for both websites and users. And what they serve up might be safe for a couple days and then the ad will be rewritten with malicious code added.

I would NEVER subject my users to any API google services on my sites. If revenue is a must I would do it with partnerships with vendors and build it within my own site rather than ever use an API service from anyone, especially Google.


40 posted on 02/26/2019 6:09:47 AM PST by Openurmind
[ Post Reply | Private Reply | To 20 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson