Hacker News new | ask | show | jobs
by damncabbage 4705 days ago
Why bother with session cookies when you can just throw up an official-looking login dialog on the google.com domain and just steal credentials from everyone not aware enough?