Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Also, I’m also surprised an XSS attack like hasn’t yet been actually used to harvest credentials like passwords through browser autofill[0].

It seems like the worm code/the replicated code only really attacks stuff on site. But leaking credentials (and obviously people reuse passwords across sites) could be sooo much worse.

[0] https://varun.ch/posts/autofill/



Chrome doesnt actually autofill before you interact. It only displays what it would fill in at the same location visually.


but any interaction is good for Chrome, like dismissing a cookie banner


Time to add 2FA...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: