|
|
|
|
|
by merb
1978 days ago
|
|
> Except that without SSL, some JavaScript could be injected to grab the password completely outside of the RSA encryption. So assuming there is already a MITM who wants the password, all you'd be doing is making his attack slightly more complicated. how does ssl prevent you from that? it doesn't. |
|
Without this kind of authentication, encrypting the connection would be pointless.