5 ms·
Not necessarily. The login page could be http, but as long as it posts to an https address, the password is never transmitted in plain text.
by IbJacked 12y ago
Not necessarily. The login page could be http, but as long as it posts to an https address, the password is never transmitted in plain text.
- fooyc 12y agoIf your login page is HTTP, your HTTPS receiver is useless. A MITM can just change the form's target URL in the HTTP login page. On inject any scripts.