Ask HN: How dangerous is external JavaScript included with govt/banking sites?

https://news.ycombinator.com/item?id=36361915
by mixmastamyk • 3 years ago
2 1 3 years ago

Hi HN. Yesterday was at the IRS "Direct Pay" site:

- https://directpay.irs.gov/directpay/payment

and here is where the JavaScript it uses is loading from:

- irs.gov

- google-analytics.com

- googletagmanager.com

- medallia.com

IRS requires you to provide extensive information to pay taxes online.

I've also seen a bank including something called "launchdarkly" as well, which does not inspire confidence either. Can't log in without it loaded.

So, isn't this a data leak and could be dangerous? Does google and medallia know my SSN, AGI, etc now?

Or does https prevent form data sharing these days? If it is the case, how to push back on the spread of analytics companies being used in confidential situations?

Related Stories

Loading related stories...

Source preview

news.ycombinator.com