Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

And, congrats, your portfolio now has injected banner ads and was used to deliver a drive-by exploit. HTTPS is confidentiality and integrity.


Why can't the portfolio page inject banner ads via HTTPS?


Because the modified page wouldn't be signed with that key? This is one of the basic things https does




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: