Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> The site was an immaculate knock off ...

Then I can picture a great way, locally, to screw these knock off big times.

Either the site is a great knock off, visually similar (if not identical) or it won't fool people, right?

So what about this: what about the browser saving, locally, screenshots of the login pages you visit.

Then, when a new login is made, compare, visually, the page to what's saved and see if any saved pages are similar?

"Oops, the page www.banklng.com looks nearly identical to www.banking.com which you visited previously, they're probably trying to scam you!".



When a measure becomes a target, it ceases to be a useful measure.


I feel like PassKeys and browser-integrated password managers both solve this problem better already. And yeah they're extra things to do, but so is this.


Another step everyone will ignore because it isn't a problem for any particular person until it is.


> Another step everyone will ignore ...

Well then enforce it, at the browser level.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: