Hacker News new | ask | show | jobs
by true_religion 4368 days ago
I don't think anything can stop someone from phishing so long as we have iframes, and users trained to accept their use.
1 comments

Well yes, my point is not to use an iframe like this (unless browsers start to include their own URL bars for those, though that still seems like a terrible idea). Previously paypal opened a regular popup (an entirely new window with its own url bar) or simply redirected the page. Both of those will fully inform the user about what site they are filling their credentials into.