4 ms·
hes saying that most sites that use adsense do not require a login, thus do not need https. he is somewhat correct, but not enough for google to just ignore th
by ryanto 16y ago
hes saying that most sites that use adsense do not require a login, thus do not need https. he is somewhat correct, but not enough for google to just ignore this issue.
- ericflo 16y agoMost content sites have login systems that people use to customize their experience, post comments or upload content, etc. Millions and millions and millions of people are logged into content sites and are vulnerable to this attack. Also, I disagree on the premise that adsense is mostly used on content sites. It's used on all kinds of websites.
- elliottcarlson 16y agoMost notably would be the oodles of forums out there that are ad supported and require logging in.
- gregmuellegger 16y agoThere are sites that make use of sessions without forcing you into using an account. These are also vulnerable.
- bigiain 16y agoWell, sometimes for strange values of "vulnerable". Some of my sites use Apache::Session over non secured http connections, which makes them technically "vulnerable". The only practical thing an attacker can do with those session ids though, is to mess with some custom visitor tracking in my management backend. So perhaps my information about whether a particular inquiry visited my terms and conditions page or my privacy policy page will be wrong. I can live with that.