Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
mholt
on Jan 29, 2016
|
parent
|
context
|
favorite
| on:
Login Forms Over HTTPS, Please
Injecting JS into the page with the form isn't my main concern, even -- it's changing the form POST action to their own server rather than the one I think I'm logging into. That's much harder to detect and block without encryption.
Plaintext HTTP is scary stuff these days.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search:
Plaintext HTTP is scary stuff these days.