Hacker News new | past | comments | ask | show | jobs | submit login

What I never understood is why an attacker couldn't just mirror the user's actions to the real site and scrape the confidence image or word from there to show on the phishing site. What am I missing?



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: