Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm guessing they used XSS to perform the man-in-the-middle attack and snatch the username+password+security code, but initially it didn't work on the journalist's computer because he had NoScript installed.


On my first read, I thought it was just shoddy editing, but I think you're definitely on the right track with this.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: