Re: HTTP is just fine
Kevin Chadwick <[email protected]>
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
> > If you deliver your "information only" webpage over HTTP you have no > > guarantee that the data you send is the data the user gets. This is a > > very real issue with intermediates injecting all kinds of things into > > content (e.g. adding ads or replacing ads or injecting some kind of > > javascript doing whatever). > > And this is a real issue. When traveling I've seen javascript being > injected in site that I know don't have javascript or for a domain that > usually doesn't show up. Https sites were never affected and just worked. And yet mozilla have reduced the control over javascript in their browser without about:config!!! which is the real issue and nothing to do with https. Also, a VPN solution would be the right solution for insecure networks. That makes it a poor excuse for justifying https everywhere.. -- KISSIS - Keep It Simple So It's Securable