Hacker News new | past | comments | ask | show | jobs | submit login

It's a bit odd to think of a password as a "non-scarce resource" when they protect scarce resources.

I expect they're not often visible, though.




Actually, that brings up a potential problem for me because sometimes I do click the eyeball icon to show my password to myself.

This attack might be too slow as long as I hide the password within 30 seconds, but future versions of the attack might be fast enough to capture multiple characters, especially if the malicious website hosting the iframe knows which pixel positions will be occupied by the password box.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: