4 ms·
Unencrypted communication is also indistinguishable from a MITM attack.
by valtron 13y ago
Unencrypted communication is also indistinguishable from a MITM attack.
- mikeash 13y agoRight, but it's distinguishable from encrypted communication. We have client-side signals for those things. http means unencrypted, https means encrypted. To do encrypted-but-not-authenticated, I guess you'd need a third URL scheme for it, to know when you're supposed to get that, since you can't shoehorn it into https safely.