I do wish there was an option to safely disable all connectivity in a browser tab (forever) like with Javascript or camera access. Yes, saving the page, disconnecting your network connection, then deleting the page would work, but it's a real bother.
After first gaining popularity, the domain could later pass to someone with malicious intent quite easily, eg:
1. Tech people like HN verify the site as credible and approve of it
2. The site gains popularity and goes viral / receives significant use
3. The original author abandons the site because of costs, or simple boredom
4. A malicious actor acquires the domain and begins recording users credentials alongside IP addresses.
Conceivably, an enormous amount could be captured before the malicious recording became exposed, and (importantly) most of those whose credentials were compromised would have no straightforward path by which they could be alerted.
Other scenarios: site is malicious to begin with but set up to not transmit credentials during its first ~28 days.
Mirrors of this site with credential capture added, (hard to claim that's a flaw of this site itself, just a flaw with "this type of site being normalized").