Skip to content

Comment on Websites Must Use HSTS in Order to Be Secureparent

Comments

(It sounds like this attack depends on a complete version of the website being available over port 80)

No, it doesn't. An attacker can always connect to the website over HTTPS and proxy the content to the victim over port 80.

Hmm, yes, of course you are correct. I'm not sure why I was thinking that wouldn't be a risk.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.