Skip to content
Better HN
Top
Best
Ask
Show
New
Jobs
Search
⌘K
Exfiltrating User’s Private Data Using Google Analytics to Bypass CSP
(opens in new tab)
(medium.com)
3 points
amirshk80
6y ago
1 comments
Save
Share
1 comments
1 comments · 1 top-level
top
newest
oldest
amirshk80
OP
6y ago
tl;dr; Since a lot of websites allow google-analytics.com, 3rd party javascript code can use the fact there is no verification on the UA-ID to exfiltrate information.
j
/
k
navigate · click thread line to collapse