|
|
|
|
|
by uponcoffee
2655 days ago
|
|
Because https mitigates their attack vectors as a mitm. They can't steal the password since it's not sent in plaintext, and for similar reasons can't deliver/inject malicious Javascript. They could collect timestamps though and scrape header information from http connections to other sites. |
|
https://security.stackexchange.com/questions/29988/what-is-c...