Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
dgoldstein0
on Nov 17, 2016
|
parent
|
context
|
favorite
| on:
PoisonTap – Exploits locked computers over USB
not just unencrypted - traffic for any website that doesn't use HSTS. All they need to do is intercept a single HTTP page and then they can modify it to contain iframes to their favorite sites over http, and any site without HSTS can then be owned.
dgoldstein0
on Nov 17, 2016
[–]
Hopefully though everyone sets the secure flag on important cookies... I wouldn't bet on it, but I suspect it may be more common than HSTS.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: