• 133arc585@lemmy.ml
    link
    fedilink
    arrow-up
    31
    arrow-down
    2
    ·
    1 year ago

    It’s definitely not the case that it’s useless. A MITM can embed malware into the page it returns if you aren’t being served over HTTPS. It’s not just about snooping on sensitive data going one or both ways, it’s about being sure that what you’re receiving is from who you actually think you’re receiving it from.

      • 133arc585@lemmy.ml
        link
        fedilink
        arrow-up
        3
        arrow-down
        2
        ·
        1 year ago

        Indeed. See my edit on the parent comment–I noticed that the website provides commands to the user to run, which makes it ripe for MITM attacks: if the user is copying-and-pasting commands to run into their shell, those need to be served over HTTPS.