Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Demonstration video has the researcher sniff passwords from match.com, which uses TLS. The catch is they aren't using HSTS and so they are vulnerable to sslstrip.


True, using a vpn gives you control over "an" encryption layer for your traffic, relying on the sites https will always be less ideal.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: