Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

no. these guys are legit. they work in our sandhill office. They're not out to steal your login credentials.


If they're legit, why are they not using oAuth?


We are using Google's oauth2 protocol. No user password is stored or even ever transmitted to our server.


Well I'm not at a Mac so I can't confirm but it's unfortunate to see such misinformation in this thread. I apologize for repeating it, I was too trusting of other comments.


Since you are framing in the login with webkit, why not show the URL as well? User's need to see htts://google.com or they'll assume it's a phishing attack.


How is this actually any more secure? It's pretty easy to display a legit (but "fake") URL while your phishing form is displayed in the webview.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: