Hacker News new | ask | show | jobs
by boomlinde 1501 days ago
> If it's for some commerial or sensitive thing then yeah, just HTTPS is okay.

It wasn't before the attacker inserted themselves, but now it is and there's a credit card form for a seemingly legitimate service on your site.