Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> I would love to see if you can prove this.

Go to https://accounts.firefox.com/signin and view source. Note that it loads https://accounts-static.cdn.mozilla.net/bundle-75dd38d5a7f98... and https://accounts-static.cdn.mozilla.net/bundle-75dd38d5a7f98....

The signin page itself may be edited at any time to point to different files, or to additional files, which load JavaScript which steals your password and sends it to Mozilla's servers. Game, set, match for your security.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: