Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Loading JavaScript from non-localhost while running the application locally #9

Open
leuchtetgruen opened this issue Jul 13, 2023 · 1 comment
Labels
enhancement New feature or request

Comments

@leuchtetgruen
Copy link

leuchtetgruen commented Jul 13, 2023

As I need to enter my vanmoof credentials into this application I'm quite cautious about where this data might end up.

So I installed the application locally and opened it in the browser, checking if any sources are loaded that do not come from localhost, which would eventually put me at risk of having my vanmoof credentials stolen.

Unfortunately I realized that this is the case. The application loads a script from the authors site. ( https://plausible.grossartig.io/js/script.js )

I'm not implying that this happens out of malice and that the author of the script is trying to steal credentials. If I understand it correctly this script is used for analytics and tracking.

However I would recommend to not load that script (at least if the application is running locally) in order to keep up trust in the system that the author created.

@Justus-D
Copy link
Collaborator

Yes, you are right. I will consider excluding analytics when run locally. Will update this issue when implemented. For now, just block the script locally in your browser.

@Justus-D Justus-D added the enhancement New feature or request label Jul 21, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants