Hacker News new | past | comments | ask | show | jobs | submit login

Edit: Realised I was being dumb here. I get it now.



If you can sniff other users' cookies, you can get their passwords. Good thing no one reuses passwords across sites!


Where the proof-of-concept shows the password in an alert box, a malicious implementation can send it to a remote server. What his proof-of-concept page does, any website can do.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: