Hacker News new | ask | show | jobs
by Eiwatah4 4475 days ago
What's stopping the attacker from reading the user's browser data and replaying it to Google?
1 comments

Cookies are not arbitrarily sent to any server. If Google has a separate subdomain they use for authentication (say login.google.com), they can instruct your browser to only send the relevant cookie to that subdomain.
Good point, though it sounds like it'd very challenging to train users to notice the absence of a special image... especially when it's normal for that image to disappear whenever they use a different browser or clear cookies.
Agreed. Yahoo actually tried that for a while, but I believe they stopped using it for that very reasons: people don't notice.

http://security.yahoo.com/sign-seal-000000996.html