Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

My reading is that it's not necessarily phishing because they wouldn't need to ask the user for any information. All that would be required is for the user to be signed into the targeted webapp.

It could be totally automated. But, since the attacker doesn't get the response, they couldn't necessarily do anything with that. That doesn't make this any less dangerous, as in the bank example, you don't necessarily need to see that your transfer was successful in order to get the money.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: