Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Okay, so say I submit a pull request for a phishing domain pretending to be an alias of something, and months/years later trick you into visiting it. Seems risky to me.


This would only be risky if I got phished into visiting your phishy domain AND was stupid enough to consciously want to enter a password into it, in which case the risks are the same as if I used a human-memorized password.

My password "manager" doesn't automatically fill in passwords until I consciously ask it to.

But some amount of human oversight over those pull requests would be in order.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: