Skip to content

Comment on Chrome 19 doesn't respect basic auth details embedded in the URLparent

Comments

That's a ridiculous reason. The most recent version of IE that supports the syntax already hides the username:pass to completely solve this problem.

Opera does the same thing.

Firefox asks if I want to log in then does the same thing.

The pre-change version of chrome I have does the same thing.

It's not a ridiculous reason at all.

The phishing attack occures when you look at the URl before clicking on it.

http://www.microsoft.com:getwindowsforyourcomputer.etc@evils... looks safe for civilians.

...and how is that different from

    <a href="http://evilsite.com">microsoft.com</a>

?

It looks different in the status bar, which is the important bit.

Like Dylan16807 said - it doesn't. Chrome already hides "user:pass" bits in the status bar.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.