Browsers are not supposed to let javascript access the DOM or events in a cross-domain iframe, is that not correct?
Correct, but it's still possible for the parent page to overlay invisible textboxes and buttons in order to capture input.
Wow, what a tire fire the web has turned out to be.
Can we just throw the whole thing out and start over? I miss the 90s...
Why not implement a good 2FA then to avoid the problem entirely? The way I see it if someone can steal your bank login details using iframes as a weapon then the bank is doing something wrong. Banning pop-ups entirely would force the banks to shape up
Isn't it easier to set X-Frame-Options to deny or sameorigin?
Yes, absolutely. But that didn't work on some older browsers (like MSIE7 and earlier), so some sites settled on weird "solutions" like this one...