3 ms·
Sounds like we were always on the same page... I never said an attacker can't do this. I'm saying an attacker can't do a s/https/http and have a user end up at
by steakejjs 12y ago
Sounds like we were always on the same page...
I never said an attacker can't do this. I'm saying an attacker can't do a s/https/http and have a user end up at an HTTP login page, where the attacker can sniff credentials.