Hacker News new | ask | show | jobs
by Latty 1096 days ago
So some news site you read on gets hacked and they install malware that means when you move to another tab, it changes the tab to look like a log in screen for say, google, and when you go back, you log in. This has been seen in the wild, and it is very hard for a human to catch, we assume we had a tab open and log in. A password manager will refuse to do it because it isn't the right domain.

Yes, of course all of these kind of attacks can be avoided by "just don't do anything dangerous", but in the real world we are all flawed and mess up. No human can be perfect, and relying on never making a mistake makes you vulnerable. Anyone serious about security makes it hard to do the wrong thing.

Hardware security keys are an even better solution, but not every site supports them. Both is by far the best option.