Hacker News new | ask | show | jobs
by passfree 4392 days ago
This is so wrong in some many levels.

1. They should not ask for any password first of all 2. They post the password to their server when they could have checked it on the client 3. The password is sent as GET meaning that it is in the URL and it will be recorded in your history and perhaps anything else that keeps log of the URLs you visit

100% fail