5 ms·
No and yes.
by tuxone 8y ago
No and yes.
- m-ueberall 8y agoAre you sure they have full access to your TLS certificates? Or can't you bring your own in this case?
- tuxone 8y agoThey host the website thus they can inject anything anywhere in the body before https kicks in.
- dan1234 8y agoIt depends how the code is being injected. If they’re using a an output filter on the web server, they could do it before the encryption stage. See http://nginx.org/en/docs/http/ngx_http_sub_module.html http://nginx.org/en/docs/http/ngx_http_sub_module.html & https://httpd.apache.org/docs/2.4/filter.html https://httpd.apache.org/docs/2.4/filter.html