3 ms·
With HTTP an attacker still has to MITM the connection between you and the mirror operator. So, definitely not "everyone".
by trulyrandom 8y ago
With HTTP an attacker still has to MITM the connection between you and the mirror operator. So, definitely not "everyone".
- DoctorOetker 8y agothe moment we are talking about monitoring user's software base, we are practically already talking attackers at the skill level of nation states, so yeah "everyone" in the subset of plausible attackers.
- cryptonector 8y agoThat includes: coffee shops, ISPs, employers, everyone who can hack their routers, anyone who can spoof DNS, etc. That might as well be "everyone". STOP IT. Though shall use HTTPS.
- trulyrandom 8y agoFair enough. I agree that HTTPS is valuable here. I was just being overly pedantic, my bad.