upvote
JavaScript (and other forms of executing logic within the browser) have made the situation worse, though.

To me, there's a big difference between a domain misread and actively malicious code running in the browser context as a design point.

reply
If a malicious site gets your password, I'm not sure why it matters whether it happened in the frontend or not.
reply