3 ms·
The reason I'd advocate in more public settings is that things ought to be secure-by-default, and that adopting security only upon realizing its necessity is a
by _Nat_ 5y ago
The reason I'd advocate in more public settings is that things ought to be secure-by-default, and that adopting security only upon realizing its necessity is a hazard-prone policy that constantly backfires.
But for a specific example of something that could go wrong: someone could inject malicious content into a non-secure page. The original content might be plain-text, but a man-in-the-middle can still inject whatever they like regardless.
As a common example of a simple attack: an attacker could man-in-the-middle people who connect to a nearby wireless network. Notes:
1. There're a bunch of ways that an attacker could get people to connect to their network. Examples: spoofing a legitimate network; setting up a password-less network; putting up a poster falsely advertising the SSID/pass to a network that falsely purports itself to be official; they're an actual employee of the establishment and just compromise the legitimate network; they're a remote-hacker who's exploited a vulnerability in the router.
2. The attacker could do lots of random stuff. Examples: they could inject malicious code; they could inject misinformation to facilitate scamming someone; they could insert ads; steal CPU-time/electricity for crypto-mining; they could just put gross porno on everyone's phone in a restaurant as a troll. Or something else. Or multiple things.
3. The original site being just plain-text doesn't really matter; the attacker can replace the entire thing without even contacting the real website. Or they can get the real website, then add other stuff to it.
The simple rule-of-thumb for website-operators is to just keep everything secure(-ish, if we're being realistic).
---
Further reading:
1. https://www.youtube.com/watch?v=_BNIkw4Ao9w https://www.youtube.com/watch?v=_BNIkw4Ao9w
2. https://www.troyhunt.com/heres-why-your-static-website-needs-https/ https://www.troyhunt.com/heres-why-your-static-website-needs...