Hacker News new | ask | show | jobs
by adn37 5624 days ago
Attacker sits at network / ISP level, and can therefore inject any (js, ...) payload in non-https web pages, on the fly.