Hacker News new | past | comments | ask | show | jobs | submit login

If these guys got hacked, they could very easily harvest your bank and email passwords.

I don't think so, because secure sites will use SSL, and your browser does certificate verification.




Sometimes yes, HSTS sites would be harder to crack.

However, many people still manually enter website urls (citibank.com) which redirects to https. If the DNS points citibank.com to a fake citibank phishing site, they simply wouldn't redirect to an https site at all.

Very savvy customers may notice that they aren't connected vis https; most people wouldn't.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: