5 ms·
In that case the html text of the page could be replaced by the attacker so the download link points to an https link.
by huuuz 5y ago
In that case the html text of the page could be replaced by the attacker so the download link points to an https link.
- peckrob 5y agoThis absolutely can happen. A few years ago I discovered [0] Atlanta Airport's public WiFi was injecting ads into non-https pages. A malicious actor changing download links is not a far fetched possibility. [0] https://twitter.com/codelemur/status/1052285395575164929?s=20 https://twitter.com/codelemur/status/1052285395575164929?s=2...
- MauranKilom 5y agoAt least it can't be an HTTPS link to the same domain. But even if a user notices this, it's not worth a lot in the age of CDNs on weirdly abbreviated separate domains...
- Semaphor 5y agoIt’s for https sites that link http downloads.
- falcolas 5y agoFirefox already aggressively alerts if you're not on an SSL secured page. They didn't for downloads.