Re: HTTP is just fine

Julien Vehent <[email protected]>
Newsgroups gmane.comp.mozilla.security
Message-ID <[email protected]>
On Fri 20.Nov'15 at 18:30:51 +0100, Ben Bucksch wrote:
> Kurt Roeckx wrote on 20.11.2015 10:05:
> >I've seen javascript being injected
> 
> Me too. A lot. And 99% are *not* on the network level.

Seems to me that if HTTPS protect you from 1% of unwanted javascript
injections, it is well worth the deployment hassle.

Deployment which, by the way, is getting so much easier nowadays that
it's been a long time since I've heard any sysadmin complain about it.

- Julien
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.