Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is Troy we're talking about - I strongly doubt he'd do anything like that without full disclosure.


I think the point of gp is to say that once you submit your password, you have no control of where it goes.

Maybe a malicious copy of the website exists at lots of LevenshteinDist=1 domains. Accidentally typo the domain and get pwned, thinking you are submitting it to an ethical security researcher's tool, but actually getting phished.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: