Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
If you're using Polyfill.io code on your site – remove it immediately (theregister.com)
131 points by moose44 on June 26, 2024 | hide | past | favorite | 10 comments



Comments moved thither. Thanks!


When the "right way" is harder than the "wrong way", you are guaranteed to get things done the "wrong way".

CDNs are used, because not using CDNs is made unnecessarily hard.

Want a local version locked copy? Select one of the dozen mutually incompatible package managers. Then select one of the dozen buggy and slow mutually incompatibile build systems. Then rewrite your app for CJS or ESM depending on the library, because ESM was made purposefully incompatible.

Want to use a CDN? Copy and paste this one line in your HTML.


Can't you just download the js file and save it next to your html files and then link to it from your html?


For many assets yes, and it's something I do quite regularly.

But many assets (especially CSS) rely on relative files - and we have apparently collectively decided that directories or other bunches or files is somehow a totally different thing than a file and need fundamentaly different logic - so just using the CDN makes you not have to worry about this.


Yes, of course. I think he means all the to manage a big project's dependencies. For a small or static website, you could manage all of those manually.


>Polyfill.io is used by academic library JSTOR as well as Intuit, World Economic Forum, and tons more.

> Since February, "this domain was caught injecting malware on mobile devices via any site that embeds cdn.polyfill.io,"

This kind of attack seems difficult to detect and ruthlessly effective. Imagine how much money they could've made by selling fake Davos tickets.



It's still an important PSA


yep, which many have read and are discussing, over there.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: