Shreyans Mehta

CTO, co founder Stealth Security, Inc.

JavaScript Injection- Good for Fraud Detection, Bad for Security

By Shreyans Mehta on Jun 18, 2018 2:24:00 PM

The wide availability of attack components on the dark and public web makes it easy even for novice cybercriminals to conduct a successful attack on a website, API, or mobile application. With automated, ‘bot’ traffic quickly eclipsing legitimate user activity at some organizations, IT security teams, along with fraud teams, are keen to implement defenses to detect automated attacks. The goals of these two teams are similar, but their approaches are markedly different.

Will businesses adopt Google’s new Invisible reCAPTCHA, or go with a vendor's solution? Yes.

By Shreyans Mehta on Mar 28, 2017 3:59:00 PM

Hi, I’m Shreyans Mehta, CTO at Stealth Security.

Most web application interface protection (WAIP) vendors rely heavily on JavaScript injection. Why? Because it’s easy, powerful, and been in use for decades for various functions, such as activity tracking for marketing. Alternatives, such as CAPTCHA and reCAPTCHA, were either too demanding on users or were easily defeatable via Optical Character Recognition (OCR) used by attack tools.

That's about to change.

