Hacker News new | ask | show | jobs
by seanwilson 2036 days ago
> You're not submitting data to him, so no benefit to protect you there.

This is a common misconception. If a page is using http, an attacker could add a sign-up form, a login form, a payment form, a malware download etc. or anything they want to the page to steal entered data or just redirect you to another malicious site, anything they want.