3 ms·
If a page doesn't use HTTPS, even if it is cats, you cannot trust that the traffic has not been modified in transit. You try to load a cat but a network attacke
by jaas 6y ago
If a page doesn't use HTTPS, even if it is cats, you cannot trust that the traffic has not been modified in transit. You try to load a cat but a network attacker can add malware or mining code or a worse exploit.
Every page needs HTTPS because you can't trust any content sent to you over HTTP. You don't know if it's "just a cat picture."
- bullen 6y agoOnly routing owners can modify the cat picture, do you think they can afford to when the browser does not "run" the cat picture?
- josephcsible 6y agoImage decoders occasionally have RCE vulnerabilities.
- bullen 6y agoI think the solution in this case is to not execute code in pictures rather than removing HTTP? Also I'm starting to suspect the downvoting feature is used a sadistic tool, just keeping karma up so you can punish people.
- johncolanduoni 6y agoThey don't intentionally execute any code, they do sometimes have a vulnerability that allows memory corruption in a way that can be exploited to run attacker-provided code. If you're not familiar with this omnipresent class of exploit, I wouldn't hope for many people on HN to take your advice on whether a security measure is needed or not seriously. Even if your comments were underlined and flashing on the page instead of grayed out.