Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

can you explain how this is a charade? I would think that posting my username & password from a http site to a https site still does ssl negotiation before sending that username and password along a network pipe. Doesn't sound like a charade to me.


The only problem is that someone can MITM your connection to the http page and send you back javascript that steals your password.


Or just change the form so it POSTs to their secret evil server, rather than to the secure site.


It eliminates the positive feedback browsers normally present. No positive feedback is bad news (see sslstrip).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: