Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's worse than that. In the web app use case, if the browser is sending cleartext passwords to the server, all an attacker has to do is hijack the server IP with BGP, get a DV SSL cert and slurp up all the passwords.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: