3 ms·
I would go one step further and block form input when you are on an HTTP site, to forms that go to HTTPS. This would end the charade of "secure" log-ins on an H
by iam 15y ago
I would go one step further and block form input when you are on an HTTP site, to forms that go to HTTPS. This would end the charade of "secure" log-ins on an HTTP page by forcing the login page to be an HTTPS page.
- etherealG 15y agocan you explain how this is a charade? I would think that posting my username & password from a http site to a https site still does ssl negotiation before sending that username and password along a network pipe. Doesn't sound like a charade to me.
- mnutt 15y agoThe only problem is that someone can MITM your connection to the http page and send you back javascript that steals your password.
- capnrefsmmat 15y agoOr just change the form so it POSTs to their secret evil server, rather than to the secure site.
- burgerbrain 15y agoIt eliminates the positive feedback browsers normally present. No positive feedback is bad news (see sslstrip).