|
|
|
|
|
by 8organicbits
201 days ago
|
|
Then what? The user presumably sees TLS certificate warnings since you don't have valid certicates. HSTS would prevent downgrades to plain HTTP and is pretty common on sensitive websites. Isn't the better advice to avoid clicking through certificate warnings? That applies both on and off open wifi networks. There is a privacy concern, as DNS queries would leak. Enabling strict DoH helps (which is not the default browser setting). |
|
This ones known. Therefore I just cannot believe that those who wrote the open letter did not even though about such significant events from the past year, I remark the past year, or even on zero-days.
We are talking about people connecting to an unknown unsupervised network, that we do not know what new vulnerabilities will be published on main stream also, and the ones of the open letter know it because they are hiding behind the excuse of "rarely".