Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Loading third party JS is increasingly common for a lot of sites, and I tend to raise it when doing security reviews

What kind of pushback do you get and how do you handle it?



To be honest I'm a external security assessor/pentester and I've not had much pushback from clients on this. That said I don't always get visibility of whether they implement our recommendations or not :)

To me, it's not really a debatable point that loading JS from a source you don't control implies trust in that source and therefore a risk that if they are compromised it affects your site.

Whether that risk is ok for a business depends on a number of factors like :-

- How trustworthy are the sources they're loading from? - What reviews have they completed on the security of those sources? - Do they have contracts in place with those sources that cover the requirement for security?




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: