Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That was my first assumption too, but Wireshark doesn't show anything going across the network as I type, and nothing that looks incriminating when I click "donate" with text in the password box. It looks like it's entirely client-side JavaScript as it claims to be. Kind of disappointing, actually.

edit: ...Unless it's clever enough to only be evil some fraction of the time. I didn't actually check through the code.



Theoretically, it could store the password in a cookie, and later retrieve it, along with (somehow) a gmail id.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: