3 ms·
The layman clicks on links that say "you have a virus; download this tool to remove it". They then click 'Yes I authorize' to verify that the downloaded program
by nanoscopic 9y ago
The layman clicks on links that say "you have a virus; download this tool to remove it". They then click 'Yes I authorize' to verify that the downloaded program should be allowed to corrupt their machine.
I fail to see how the bank changing their website to HTTPS is going to save the average Joe.
There are so many websites and things that operate over HTTP that make our machines vulnerable, that I think it is foolishness to use a link that could be MITM to begin with.
That is, it seems to me, that if you simply avoid ever using wireless there is no danger of MITM. I could see that XSS could be done on some sites with ads, and that would be worsened by lack of HTTP.
Is it as simple as "Don't use wifi. Use adblock. HTTP/HTTPS then no longer matters." ?
- biggio 9y agoWith the layman example, you are describing man in the browser attack. It doesn't matter if you use wireless or not.
- yjftsjthsd-h 9y agoThis sounds a lot like "we can't protect average joes from themselves, so let's not bother adding protections"? Sure there are always other attack vectors, but that doesn't excuse ignoring the ones that are easy to fix.