I was at a tech meetup last week and saw someone demo a plain HTML page that perfectly cloned a bank login. No scripts, just clean HTML and CSS. That’s the problem—phishers don’t need JavaScript to steal your info. They use simple forms and links that look exactly like the real thing. You’re right that HTML is the web’s foundation, but foundations can hide cracks. Reddit flagging it isn’t saying “HTML is evil,” it’s saying “hey, this plain page could be a trap.” We already do this with suspicious links and attachments. Adding a small friction point for plain HTML isn’t
01:04 PM