Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Because every submission should have a pessimistic, cynical reply: I expect this to be used to its full potential by phishing sites.

Aside from that: finally.



Christian Cantrell, from Adobe, demonstrated a similar phishing attack vector: https://www.youtube.com/watch?v=XQXFO9NNO8g

"This won't end well..."


How would that work, a full-screen emulation of safari in js?


It would be trivial to imitate Mobile Safari's chrome with "actuallegitdomain.com" in the address bar instead of "actuallegitdomain.com.ooo.ag" or resorting to IDN tricks (since most browsers, and I think Mobile Safari too, show the xn--wh4t3v3r.com version).


I would think a full-screen emulation of a bank app or something. Phishing email sends you to a link that "opens" your bank app and asks you to sign in.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: