Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Google is hiding PATH not DOMAIN_NAME, which makes this phishing activity EASIER to detect. That's the point of the feature!


Except it isn't phishing.


That's debatable. I think the only difference is maybe the intent of the attacker?


As I understand it, phishing is when you obtain sensitive information from a user while impersonating a site the user trusts. I don't suppose there's any exchange of sensitive information taking place here (nor is it possible if I am not mistaken, unless the website creator has any bad intent).




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: