Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You have a point here. Perhaps the real solution is that we should make the browser throw a fit when someone tries to input a "password" into a page/authdialog that has no security as well.


Then the altered page just specifies that it is not a password field, and emulates it with javascript or whatever. So that could only work for sites where a password manager was used, assuming the user doesn't just go ahead and type it in themselves.


Not just passwords, any form submission. :P


you could simulate forms with JS and images. You dont even need to submit, once a user fills the form exfiltrate it through a JS image load, such as this http://www.lanmaster53.com/2011/05/stealth-cookie-stealing-n...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: