When I first read the story I laughed because it's the usual case of a journalist reporting half truths and blowing things out of proportions to sell a story. He seems to inicate that now browsers have phishing alerts people have suddenly forgotten the years of anti phishing advice they have had drummed into them.
As to Firefoxs password function going off the domain as opposed to the full url I'd say this was the writers choice as opposed to a flaw.
QUOTE
seems to affect all versions of Firefox, and may also affect Microsoft's Internet Explorer.
QUOTE
Chapin has informed Microsoft of the problem.
So the 'problem' definetely exists in Firefox but possibly not in IE so he goes and informs the Microsoft for whom it may not be an issue but apparently does not inform Mozilla?
QUOTE
their information can be stolen in this way when visiting blog and forum websites at trusted addresses.
I have yet to see a forum script that would allow this type of HTML to be posted.