Remix.run Logo
OkayPhysicist 2 hours ago

None of this required Javascript. At all. The same potential attack could have been done with good ol' forms. Sure, you think you're signing into "BigBensSuperStore.com", but you're actually handing your credentials right over to "BigBensSuperStore.net".

LocalH an hour ago | parent [-]

JavaScript (and other forms of executing logic within the browser) have made the situation worse, though.

To me, there's a big difference between a domain misread and actively malicious code running in the browser context as a design point.

saghm 23 minutes ago | parent [-]

If a malicious site gets your password, I'm not sure why it matters whether it happened in the frontend or not.