Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

With an HTTP connection, it becomes easy for an attacker in the middle to prompt the user to re-enter their password and have it re-transmitted in the clear.

I'm surprised more attackers don't do this.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: