|
|
|
|
|
by bonyt
3074 days ago
|
|
Well, sslstrip still likely works on websites that don’t use HSTS, or that you’re visiting for the first time. I suppose the HTTPS Everywhere plugin might mitigate this. Do any browsers try https first yet? Now that I think of it, I guess many search engines now use HTTPS with HSTS and will send you straight to the https site if it knows of one, so that’s good. https://moxie.org/software/sslstrip/ |
|
This works for most things - for a few things I'll open an incognito window in Chrome, which simultaneously turns off extensions and doesn't send my original cookies, and I'll be careful about what I do in that window (certainly no logins to sites I care about). This is generally enough for e.g. reading some random news site that doesn't support HTTPS at all.