|
|
|
|
|
by rlidwka
3998 days ago
|
|
It doesn't change anything. As some people used to say, "security is binary; you either are secure or you are not". While it's useful for phishing pages to be interactive, it's not strictly necessary: ---- "Your paypal account is locked, because we suspect it to be hacked. To unlock it, please call our tech support (phone number 1-234-56789) and tell them your paypal password to prove your identity (and CVV of all the credit cards pretty please)." |
|
I'm certainly not saying there's no issue here - your example perfectly demonstrates a realistic and dangerous use case - I'm merely pointing out that omitting such an important aspect of the vulnerability in the repo readme is disingenuous and materially changes the severity of the issue. To be honest, the omission actually smacks a little of clickbait.