5 ms·
You could load gmail or facebook or any other site in an iframe and tell the user to login, but you would intercept his credentials with javascript.
by gregorkas 13y ago
You could load gmail or facebook or any other site in an iframe and tell the user to login, but you would intercept his credentials with javascript.
- waltz 13y agoHmm that is a fair point. Maybe a more secure alternative to iframes can emerge. Something like Chrome's WebViews. Even though as of right now native browsers can intercept your data as well, it's a matter of trusting the tool.
- gcb0 13y agoHow exactly do you use javascript cross domain like that? i'd love to know.
- gregorkas 13y agoYou don't. You register a key press event listener on the main page and when the user types into the iframe, you can catch the strokes. Example: http://www.jayssite.com/misc/iframesample.html http://www.jayssite.com/misc/iframesample.html (not my site, I googled it)
- gcb0 13y agoi don't think this example is cross-domain...