Re: HTTP is just fine

Kurt Roeckx <[email protected]>
Newsgroups gmane.comp.mozilla.security
Message-ID <[email protected]>
On 2015-11-19 17:40, Hanno Böck wrote:
> If you deliver your "information only" webpage over HTTP you have no
> guarantee that the data you send is the data the user gets. This is a
> very real issue with intermediates injecting all kinds of things into
> content (e.g. adding ads or replacing ads or injecting some kind of
> javascript doing whatever).

And this is a real issue.  When traveling I've seen javascript being 
injected in site that I know don't have javascript or for a domain that 
usually doesn't show up.  Https sites were never affected and just worked.


Kurt

_______________________________________________
dev-security mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.