“Not a hash, not a token reference, but the literal password string, baked directly into the client-side JavaScript that gets shipped to every visitor’s browser.” He claimed this password could ...