Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Strict transport security (http://en.m.wikipedia.org/wiki/HTTP_Strict_Transport_Securit...) is an attempt to prevent exactly this. However assuming that the user is always on a MITM'd connection, a preloaded list in the browser becomes necessary.


Yes, doing this attack after a site is already publicly known is hard because of HSTS (if Github uses it), but slowly caches will expire and browsers will reset themselves, and the amount of http traffic will increase a lot.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: