4 ms·
Not having an http site doesn't help in a MITM scenario as the attacker will happily serve up an http site even if you don't.
by biot 9y ago
Not having an http site doesn't help in a MITM scenario as the attacker will happily serve up an http site even if you don't.
- Darkenetor 9y agoThe only solution is to always go for the HTTPS resource disregarding any suggestion. On browsers a strict configuration of Smart HTTPS [0] covers that, for everything else I think the best solution would be to intercept all HTTP traffic, request the HTTPS counterpart (and decide if falling back on failure is acceptable instead of just dropping the connection), then serving locally the decrypted response. Worse than properly requesting the right one from the start but harder enough to exploit. [0] https://mybrowseraddon.com/smart-https.html https://mybrowseraddon.com/smart-https.html
- pmoriarty 9y agoIt's true that it doesn't help once the user has been MITM'ed. But before that happens, if the user always goes to the http address and it works for them (whether by legitimate redirect or by the legitimate site simply supporting http) it lulls them in to a false sense of security, and a belief that going to the http address is ok. So the idea behind having the http address be broken from the start is to make the users see that the address they're trying is broken, and therefore the wrong one for them to use. Hopefully at that point they'll investigate why (perhaps complaining or talking to their sysadmin, if they have one), and be straightened out by someone providing the https link to them (or the more tech-savvy users like the OP figuring it out for themselves).
- cpach 9y agoHSTS helps for this.