Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I doubt that would make things a lot safer. With permission to modify only the stylesheet, one could already change the login form to phish your password.


How? I agree that something like that would be risky (you could style the delete button to say "reply"), but I'm not sure how you could do that. Stylesheets can't change a form's action.


I was thinking it would be possible by crafting pseudo elements to a replacement login form, but after reading some more that actually does not seem possible. Maybe one could make the email composition form look like the login form under some conditions.

On the other hand, reddit allows people to upload stylesheets for their subreddits, they only re-host the images in them and that seems to have worked out well.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: