Hacker News new | ask | show | jobs
by startling 3526 days ago
So, what's stopping the wrong site from making those requests to your bank and proxying the image?
1 comments

The bank sets a cookie on your machine and only displays the image if you have the cookie. You won't get the image on a machine you've never used to log in before.