Hacker News new | ask | show | jobs
by penagwin 2381 days ago
Redirecting to https is still problematic though.

Let's say your websites homepage only uses http but the login form is over https. You can MiTM the homepage, and change the login link to haX0r.xyz and then proxy the login.

1 comments

Is that the case here?