Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think the expectation is that any halfway decent web site will make whatever changes are necessary to avoid the warning.


Sure, but halfway decent web sites aren't the ones hosting malware.


The problem is not sites hosting malware. The problem is man-in-the-middle attacks on javascript loaded in the clear on sites otherwise using HTTPS. If an attacker can replace a bit of JavaScript that gets loaded into the page, that somewhat defeats the purpose of using SSL.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: