Disturbed by @DonorBox-powered UI's interaction with Web's security model: it asks for bank login/password on origin that's not the bank's.
1
3
The criminal could be someone who sets up a site similar to yours, using something that looks like @DonorBox, but steals the password
1
1
5
It could also be somebody who hacks the @yimbyaction website, since users entering bank passwords into that site makes it a valuable target
1
5
The fundamental problem is that the browser URL bar says who you're communicating with. Users should never enter bank password at not-bank.

Aug 18, 2017 · 3:19 AM UTC

1
1
7
Teaching users that that's OK sometimes is teaching them to do things that put them at very serious risk online.
4