Bump.
This hack does make vB vulnerable to steal passwords via phishing. At the minimum, people should know that clicking on a spoiler button shouldn't open a new window. On a fast enough phishing server, the user may not even notice (assuming the phishing server served up already cached images).
tick tock
Also, you can't nest the spoilers in IE. If you put a spoiler inside of a spoiler it just craps out.
|