5 ms·
Nit: the site should be serving all of its assets over https.
by khamoud 8y ago
Nit: the site should be serving all of its assets over https.
- nikanj 8y agoOtherwise someone could eavesdrop this publicly available material, or MITM the content for the benefit of...why? This new https craze is like demanding seals of authenticity from posters on lamp posts.
- JackCh 8y ago>"MITM the content for the benefit of...why?" To insert advertisements or "helpful" messages (https://tools.ietf.org/html/rfc6108 https://tools.ietf.org/html/rfc6108)
- teddyh 8y agoSee also RFC 7258, “Pervasive Monitoring Is an Attack” https://tools.ietf.org/html/rfc7258 https://tools.ietf.org/html/rfc7258
- Sylos 8y agoThey could inject malicious code or even just ads into those http assets and therefore compromise the https connection. I also don't necessarily think that we need https for everything, but it's better to err on the safe side and if you're gonna start doing it, then you should do it properly.