3 ms·
Would having TLS on the localhost endpoint (without client certificates) make the attack more difficult? the browser would have to validate the localhost-return
by skela224 9y ago
Would having TLS on the localhost endpoint (without client certificates) make the attack more difficult? the browser would have to validate the localhost-returned cert against the attacker.com hostname.