3 ms·
That is not enough at all and there are other attacks! I can't belive in 2020 some people still need to be explained why not enforcing https is a terrible thing
by ecares 6y ago
That is not enough at all and there are other attacks! I can't belive in 2020 some people still need to be explained why not enforcing https is a terrible thing!
For instance, will a lockfile prevent someone from eavesdropping on the download of a modules through http? If so, please kindly tell me how!
- 1_player 6y agohttps prevents MITM but doesn't prevent the modules being backdoored or otherwise altered at the source. I would prefer https-only, sure, but it doesn't buy you very much security.
- ecares 6y agoWell, diasabling http by default is basically "Internet 101" here. I don't want to write an full lecture on how many attacks are possible when people don't use https. It has been commmon knowledge for way more than a decade