Hacker News new | ask | show | jobs
by graftak 1064 days ago
Except that most of these appear to be served over http, sans s.
1 comments

Is that an issue if nothing confidential is being served?
It’s prone to MITM attacks and it allows snooping for what pages are visited. Some US ISPs use(d) this vulnerability to inject ads into pages. On a public/shared network you might be vulnerable to automated attacks.
How long would US ISPs need to stop doing this, now that most stuff is HTTPS delivered anyways?