if user does not pay attention to login url show in login page and click login, fake site can get user credentials.