TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Ask HN: Why isn't HTTPS enough to protect your site?

1 pointsby 01-_-11 days ago

2 comments

zahlman11 days ago
The first lesson in cybersecurity (and I would imagine in real physical security as well) is that &quot;protect your [asset]&quot; is not well defined in a vacuum. You need to develop a <i>threat model</i> before you can sanely ask any questions about what actions you do or don&#x27;t need to take.<p>HTTPS protects against <i>one</i> specific scenario: a third party is intercepting the communication. So it protects your users against those third parties (who might never forward the request to your site, and instead pretend to be your site; or they might spy on what they say to you or what you say back to them).<p>It does <i>not</i> protect against malicious <i>users</i> trying to hack your site directly, in any number of ways. Nor does it protect against people trying to hack into your server directly (bypassing the site entirely, although they might have the purpose of damaging your site). And it <i>definitely</i> doesn&#x27;t protect against people trying to trick your users off-site, for example by sending them an email pretending to be from you.
jsheard11 days ago
Huh? You&#x27;re gonna have to elaborate a bit.
评论 #43887034 未加载