3 ms·
Imagine if when you wanted to connect to your bank over HTTPS you first had to send a HTTP request which asks permission to "upgrade" to HTTPS. This actually h
by spindritf 12y ago
Imagine if when you wanted to connect to your bank over HTTPS you first had to send a HTTP request which asks permission to "upgrade" to HTTPS.
This actually happens a lot. Most people most of the time don't painstakingly type in h-t-t-p-s-:-/-/... but rather just the domain name and the server on the other end returns a (plaintext) redirect to https. Which is why sslstrip works so well.
Sure, we have bookmarks, HSTS, tell people to look for a lock icon in the address bar but it's far from being a solved problem.
- iancarroll 12y agoHSTS preloads fixes this problem on modern browsers. Google literally has a site where you can add your site to Chrome's list (which Mozilla clones) in a few weeks. If you're using other browsers, the problem still exists but a large majority is covered by this.
- dublinben 12y agoThere's only 500 sites on that list. None of the largest banks in the US are even included. This problem is hardly solved.
- iancarroll 12y ago(There are a lot more in Canary/Beta) Banks have the ability to do it, so I wouldn't exactly pin it on a new solution being needed. If they won't adopt pinning or HSTS, then why would they adopt anything else?
- tracker1 12y agoHell, banks are some of the biggest offenders of requiring SSL3, with no TLS option...