5 ms·
If the first request is plaintext, the request can be intercepted before you ever get the redirect, inserting a trojanised login page instead.
by entropyie 3y ago
If the first request is plaintext, the request can be intercepted before you ever get the redirect, inserting a trojanised login page instead.