Hacker News new | ask | show | jobs
by viraptor 5164 days ago
Unless someone substituted the javascript served by the page over unprotected HTTP (while it was sent to you). Firesheep already showed that making similar process user-friendly isn't that hard.