3 ms·
They did respond. Kind of. http://googleonlinesecurity.blogspot.com/2009/06/https-security-for-web-applications.html http://googleonlinesecurity.blogspot.com/2
by talison 17y ago
They did respond. Kind of.
http://googleonlinesecurity.blogspot.com/2009/06/https-security-for-web-applications.html http://googleonlinesecurity.blogspot.com/2009/06/https-secur...
- sriramk 17y agobut the original attack wouldn't have changed one bit with SSL. Peter Guttman wrote a great paper on how we defend where the attackers aren't attacking. SSL in this case would have been one such example. Of course, SSL has value in other cases (sniffing, ensuring you're talking to the right site, etc) but is no panacea.