Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The real take away is that they’re sending all text typed in, including credit card and social security numbers, unencrypted to a third party.


Source? This would probably fail some compliances audit.

Most of these kind of tools (ie:HotJar) have a flag that will prevent theses data from being sent.


> In the case of Air Canada’s app, although the fields are masked, the masking didn’t always stick




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: