Hacker News new | ask | show | jobs
by LargeTomato 900 days ago
My android phone was redirected to an https endpoint.
1 comments

If the first request is plaintext, the request can be intercepted before you ever get the redirect, inserting a trojanised login page instead.