|
|
|
|
|
by RaisingSpear
814 days ago
|
|
The phisher can just pass on whatever you sign, and capture the token the server sends back. Sure, you can probably come up with some non-HTTPS scheme that can address this, but I don't see any site actually doing this, so you're back to the unrealistic scenario. |
|