Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

[deleted]


It doesn't make a difference. Just because a site is SSL-encrypted doesn't make it a site you should trust with your paypal credentials.

The only site you should trust with your paypal credentials is paypal. And the only way to be sure you're talking to paypal is to see paypal in the address bar with an SSL-encrypted session. (At least, that's what the whole web, browsers and CA's alike, have been striving to ensure is the case since the web has had encryption.)


You're not getting the core issue - the way real gateway works cannot be distinguished from phishing. "seamless" user experience confuses users and is going to create a whole new wave of phishing


The problem is that Github could open a popup with a form that looks the same, and you wouldn't be able to tell that you're not sending your credentials to Paypal only


Yeah but what to stop me from serving a fake popup over https://myfraudsite.com?


Nothing, but you can't hide that it is https://myfraudsite.com from the user since the browser always displays the URL (at least it does nowadays).




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: