Hacker News new | ask | show | jobs
by homakov 4953 days ago
>This is nothing new. Once XSS has been exploited the users are already pwned regardless of password policy.

stealing password >> XSS.