Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
simonw
on June 26, 2008
|
parent
|
context
|
favorite
| on:
37Signals "just says no" to feature request: "plea...
Yes. That's why XSS is such a serious security problem. And even if you can't steal cookies, you can still do nasty things like re-target the login form's action to point at your own server and hence steal people's passwords.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: