tomayac’s avatartomayac’s Twitter Archive—№ 19,328

  1. …in reply to @simevidas
    @simevidas WCO (web.dev/window-controls-overlay/) lets the disguise become even more perfect. Another attack vector is to start like a harmless PWA that then tries to change its identity to look like your banking software. This is why WCO is opt-in and icon and/or name changes will require a prompt.