4 ms·
This was the point I wanted to bring up; if you have your login form on a non-ssl page, it's possible for a man-in-the-middle attack to replace the "action" on
by Davertron 16y ago
This was the point I wanted to bring up; if you have your login form on a non-ssl page, it's possible for a man-in-the-middle attack to replace the "action" on the form and send your login credentials anywhere they want. To prevent this with the drop-down login, you have to make your homepage SSL, which has other drawbacks.