Hacker News new | ask | show | jobs
by coldpie 2040 days ago
I'm not trying to be snarky, just trying to understand. What are you defending against by refusing to visit a read-only, plain HTTP site?
1 comments

I’m not the parent poster, but one reason I can suggest is:

When you know about the security properties of using the HTTP protocol over internet, and proceed to visit a read-only plain-HTTP website, your attention and time are used up unnecessary on thoughts like “did the author really include this bit of content, or is it being MITM’ed?” with no inexpensive way to find out.

... but realistically, the risk of that is extremely low in this specific case.
ISPs have injected ads on http websites in past. So it has happened.