Hacker News new | ask | show | jobs
by someguy1233 3795 days ago
The fact is however, HTTPS offers massive improvements for security for the majority of users, especially those using public or shared Wi-Fi (i.e. Work or School), assuming they're using their own device. Assuming HSTS was set up, it would be impossible to strip SSL without causing most browsers to panic and refuse you access to the website.

On those types of networks, MITM attacks are extremely easy, and there are tools to do it in seconds. It may be more likely for you to get MITM'd and have them modify the signature, than for the actual website to get hacked. Combined with the fact that some people would try to download Tails across these types of network for the added anonymity.