Hacker Newsnew | past | comments | ask | show | jobs | submit | fin1te's commentslogin

Looking at the screenshot in the article, it seems that the payment screen is embedded in a light-box, as opposed to a popup.

IMO this is not a good idea. You can't see the URL, so you can't verify that you're actually entering your credentials on *.paypal.com (without checking the page source, something an average user won't do). Opens it up to phishing attacks.

At least with the current flow (and for Facebook/Twitter/etc share dialogs) it opens in a popup with an address bar. Easy to verify you're on the correct site.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: