TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Tor security advisory: exit relays running sslstrip in May and June 2020

5 点作者 jerheinze将近 5 年前

1 comment

tylerd22将近 5 年前
I remember discovering Moxie Marlinspike talking about this issue 9 years ago and he described this attack as &quot;deadly&quot;.<p>And it really is. In essence, a man in the middle converts all https links to http and proxies out the traffic. A victim would need to notice the missing https in the the url to detect this.<p>HSTS and https-everywhere browser plugin partially solves the problem.<p>I think the only viable solution is for all http traffic to be encrypted and to consider non-encrypted traffic suspect.