3 ms·
It's just basic connection integrity -- without HTTPS, there's no guarantee the user is actually getting the content that the site meant to send, and vice versa
by konklone 10y ago
It's just basic connection integrity -- without HTTPS, there's no guarantee the user is actually getting the content that the site meant to send, and vice versa. Those kind of attacks really do happen, and at scale (e.g. Verizon XUID, or China's Great Cannon).
If it's at all interesting, I laid out in detail, with examples, why I've been comfortable taking a very hard line on deprecating HTTP:
https://konklone.com/post/were-deprecating-http-and-its-going-to-be-okay https://konklone.com/post/were-deprecating-http-and-its-goin...