3 ms·
No! Stop! Why won’t this one die! MITMing is a two way street. I could intercept sensitive data, or I could shove something in that tricks the user (phishing,
by appendix-rock 2y ago
No! Stop! Why won’t this one die!
MITMing is a two way street. I could intercept sensitive data, or I could shove something in that tricks the user (phishing, etc), exploits the user agent, and more!.
“You only need encryption for the sensitive stuff” is what we did, poorly, in the late ‘00s / early ‘10s, and it was rightfully proven to be a bad idea. There’s a reason why browsers treat HTTP the way they currently do, and it isn’t because they’ve been co-opted by Big Certificate Authority.
EDIT: and as the other commenter says, there are download links.
- tcfhgj 2y agoYou don't need encryption to prevent something shoved into it without detection
- XorNot 2y agoNo but we have no "httpv" protocol scheme to require signatures but not encryption Which IMO has been a huge mistake since breaking caching proxies for networks because we want to prove authenticity and have to do secrecy as well has been quite silly.
- aaronmdjones 2y agoNo, but you do need authentication, and TLS does both.