Skip to content

Comment on Chrome 19 doesn't respect basic auth details embedded in the URLparent

Comments

It's not a ridiculous reason at all.

The phishing attack occures when you look at the URl before clicking on it.

http://www.microsoft.com:getwindowsforyourcomputer.etc@evils... looks safe for civilians.

...and how is that different from

    <a href="http://evilsite.com">microsoft.com</a>

?

It looks different in the status bar, which is the important bit.

Like Dylan16807 said - it doesn't. Chrome already hides "user:pass" bits in the status bar.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.