Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
Exfiltrating User’s Private Data Using Google Analytics to Bypass CSP | Better HN
Exfiltrating User’s Private Data Using Google Analytics to Bypass CSP
(opens in new tab)
(medium.com)
3 points
amirshk80
5y ago
1 comments
Share
1 comments
default
newest
oldest
amirshk80
OP
5y ago
tl;dr; Since a lot of websites allow google-analytics.com, 3rd party javascript code can use the fact there is no verification on the UA-ID to exfiltrate information.
j
/
k
navigate · click thread line to collapse