Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

They however still have access to the JS context and thus the authenticated session when you are on the website. They can most likely exfiltrate all the data visible on the page and maybe even the auth token for further server-side misuse after you've closed the page.


Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: