Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

There are many caveats. For example, the server and the connection must be trusted. Otherwise, an attacker can the javascript to send himself a copy of your password.

And weak password are subject to bruteforcing.

If you trust the server, rather use htaccess. Or place the document at example.com/mySecretPassword/index.html Just be careful about outgoing links.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: