So the malware should be allowed to continue stealing credit card numbers just because the site owners don't know any better?
Is that really a position you wish to defend?
So the malware should be allowed to continue stealing credit card numbers just because the site owners don't know any better?
Is that really a position you wish to defend?
As I said, and GitLab suggested, OP should at least contact them. If you contact them and they say they won't do anything, now that's a different story...
Someone will make a browser extension that uses this list to warn users?
So it sounds like does a pretty good job of fixing things
[0] https://gwillem.gitlab.io/2016/10/14/github-censored-researc...
Change the browser, change the payment system, educate the user by using plugins, propose enhanced security methods in ECMAscript. Write about how easy it is to make missteps on the net. These are all alternatives which might help in a more permanent fashion.
There is nothing a client can do when the server is compromised.
1. Instruct users never to enter card details directly into a website, but rely on a redirect to the card provider. This would change the origin. When properly setup, this should catch 99% of the problems.
2. Provide stricter browser controls, so third-party ECMAscript is not loaded into the browser by CORS. Again, instruct the user or have us make better browsers.
3. Lobby for better payment services. Here in the Netherlands, payment is done using iDEAL, on a separate origin (using redirects) and the payment is validated using a separate device.
The secondary problem is with the websites, the primary problem is with the supporting technology.
There's nothing ineffective about uncovering a problem and using transparency to create an incentive to fix it. Crude, yes, but not ineffective at all.
What GL did might be considered complicit in skimming users, especially if they acted under pressure from fraudulent shops or even the skimmers themselves (how do we know?).