3 ms·
The thing is, it only takes one non-TLS web request to be harmed. There are a number of attacks that can be done that require MITM and/or local snooping that ar
by fryguy 11y ago
The thing is, it only takes one non-TLS web request to be harmed. There are a number of attacks that can be done that require MITM and/or local snooping that are easily done at a conference like this (the TLS export-level security downgrade recently, BREACH/CRIME, etc). There were a number a few years back before HSTS was around where it would hijack people going to http://google.com http://google.com and capture their cookies before it redirected to https://google.com https://google.com. These might seem trivial now, but what will people think 5-10 years ago about the things that are possible now.