Skip to content

Comment on What are you waiting for?parent

Comments

If you are on a public internet connection you should. I could theoretically replace the content of that page with whatever I want. A crypto currency miner, some zero day JavaScript exploit that will download a key logger on your computer etc. Https helps to mitigate these sort of man in the middle attacks, even on static content.

I'm on a public internet connection, but I'm not too worried because to perform such an attack, you would have to compromise some physical network infrastructure between me and sciencemag.org, and do it in a such a way to not get yourself in trouble with the law.

It's possible sure, but it seems difficult enough to not worry about.

It's easy for an attacker on your WiFi network, in some cases.

Your WiFi network might be encrypted, which might be a broken encryption, or might be unencrypted to discourage excessive use.

You don't even have to go that far, it's usually done between you and the router.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.