Comment on Chrome 19 doesn't respect basic auth details embedded in the URLparentComments−Dylan1680714yThat's a ridiculous reason. The most recent version of IE that supports the syntax already hides the username:pass to completely solve this problem.Opera does the same thing.Firefox asks if I want to log in then does the same thing.The pre-change version of chrome I have does the same thing.−nl14yIt's not a ridiculous reason at all.The phishing attack occures when you look at the URl before clicking on it.http://www.microsoft.com:getwindowsforyourcomputer.etc@evils... looks safe for civilians.−piotrSikora14y...and how is that different from <a href="http://evilsite.com">microsoft.com</a> ?−sirclueless14yIt looks different in the status bar, which is the important bit.−piotrSikora14yLike Dylan16807 said - it doesn't. Chrome already hides "user:pass" bits in the status bar.
Comments
That's a ridiculous reason. The most recent version of IE that supports the syntax already hides the username:pass to completely solve this problem.
Opera does the same thing.
Firefox asks if I want to log in then does the same thing.
The pre-change version of chrome I have does the same thing.
It's not a ridiculous reason at all.
The phishing attack occures when you look at the URl before clicking on it.
http://www.microsoft.com:getwindowsforyourcomputer.etc@evils... looks safe for civilians.
...and how is that different from
It looks different in the status bar, which is the important bit.
Like Dylan16807 said - it doesn't. Chrome already hides "user:pass" bits in the status bar.