Re: HTTP is just fine
Kurt Roeckx <[email protected]>
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
On 2015-11-19 17:40, Hanno Böck wrote: > If you deliver your "information only" webpage over HTTP you have no > guarantee that the data you send is the data the user gets. This is a > very real issue with intermediates injecting all kinds of things into > content (e.g. adding ads or replacing ads or injecting some kind of > javascript doing whatever). And this is a real issue. When traveling I've seen javascript being injected in site that I know don't have javascript or for a domain that usually doesn't show up. Https sites were never affected and just worked. Kurt _______________________________________________ dev-security mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security