logoalt Hacker News

OkayPhysicisttoday at 7:32 PM1 replyview on HN

None of this required Javascript. At all. The same potential attack could have been done with good ol' forms. Sure, you think you're signing into "BigBensSuperStore.com", but you're actually handing your credentials right over to "BigBensSuperStore.net".


Replies

LocalHtoday at 7:42 PM

JavaScript (and other forms of executing logic within the browser) have made the situation worse, though.

To me, there's a big difference between a domain misread and actively malicious code running in the browser context as a design point.

show 1 reply