Some more things to add: 1) By using path modifiers you can mislead people on where a link will go. For example: [url]http://www.bungie.net/projects/aerospace/crimson/../../[/url] 2) Links can be disguised in [url=http://jsfiddle.net/M8bxP/]many ways[/url]. The bottom right panel acts as a single page you would see in your browser. 3) Your DNS cache can be poisoned so that even if your browser tells you you're going to google.com which is at xxx.xxx.xxx.xxx, it's going to connect you to yyy.yyy.yyy.yyy. This can also happen at any proxy or other DNS cache (eg. your ISP's). 4) Even if your browser displays the "lock" icon, all that really means is that the connection is secured between your computer and the server. It does not mean that the server belongs to the organisation it claims to.