3 ms·
> [..] a page can be modified to include malicious content, including legitimate looking forms. Sure, I've been there with "free WiFi" services injecting crap
by bArray 5y ago
> [..] a page can be modified to include malicious content, including legitimate looking forms.
Sure, I've been there with "free WiFi" services injecting crap into a page. I believe some ISPs in the US would also put JS into HTTP pages. But this is why I argue for both HTTP and HTTPS.
I think it ultimately depends on your security model. Perhaps a workaround could be to disable forms in browsers whilst in HTTP mode, disable JS, parts of CSS, etc, by default. Require that the user explicitly ask for content in an insecure way.