3 ms·
I really like this, "normal" web browsing makes it hard to be actually secure. Things like sslsniff (which basically do the exact opposite of this) make it rea
by colonelxc 16y ago
I really like this, "normal" web browsing makes it hard to be actually secure. Things like sslsniff (which basically do the exact opposite of this) make it really easy to MITM "normal" use of ssl (go to http site, get redirected to https).
I'm kinda an "all or nothing" person, so when I had previously thought about how to "solve" auto-encryption like this, I thought about requiring https across the board. Of course if you tried to browse like this, you'd have a pretty crappy experience. If you built in an auto fallback to http in case of failure, you'd have the same problem before, where any MITM can trick you to visiting unencrypted sites.
This is a good compromise of forcing encryption on the important sites (like banks), but still being practical for the real world.