Hacker News new | ask | show | jobs
by cjensen 4350 days ago
How about ordering a high-cost item from an attacker who sells on Amazon? How about AWS? How about Amazon Payments to order a service from the attacker's site?

In order to trust you with credentials, it is necessary that you show you have thought everything through. The user needs to know that you will not leak credentials. It's a very high bar. You have simply failed to clear the bar.