3 ms·
If your SSL is compromised, the attacker can insert javascript to send the unencrypted password somewhere else. That is why security experts like tpacek have r
by codexon 14y ago
If your SSL is compromised, the attacker can insert javascript to send the unencrypted password somewhere else.
That is why security experts like tpacek have repeatedly said js encryption schemes aren't secure.
- furyofantares 14y agoWhy do you say an SSL compromise necessarily means the attacker can manipulate the connection? And what about a promise between the SSL endpoint and the database?