Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
yjftsjthsd-h
on Dec 10, 2017
|
parent
|
context
|
favorite
| on:
Comcast is injecting 400+ lines of JavaScript into...
What?
charleslmunger
on Dec 10, 2017
[–]
I think the intent was to comment that extensions don't protect programs with embedded web views, like the steam store. I'd hope the steam store is using https though...
GranPC
on Dec 10, 2017
|
parent
[–]
Only on checkout pages. For the rest of the storefront they actually redirect you from HTTPS to HTTP.
charleslmunger
on Dec 13, 2017
|
root
|
parent
[–]
That's especially bad, because you can't actually see the origin or whether TLS is in use from the store's interface...
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: