3 ms·
Exactly! While such research is cool, I think this has been long solved using HTTPS everywhere. You simply can't trust the router. Without HTTPS, all you need i
by ibz 4y ago
Exactly! While such research is cool, I think this has been long solved using HTTPS everywhere. You simply can't trust the router. Without HTTPS, all you need is a honeypot router that acts as a man-in-the-middle, which is not that hard of a setup.
- cudgy 4y agoIf the bad actor is injecting malicious javascript over plain text http to the device, doesn’t that get around this? Or is it possible to force the target ios/android/etc device to only accept https packets?