Hacker News new | ask | show | jobs
by cad 3985 days ago
Front page is not behind ssl and you can sign up from there. It's easy to change form action target to a malicious url with a simple mitm attack.