Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Ah yes, I had completely forgotten about upgrade-insecure-requests. This mitigates a lot of what I was complaining of, though, as you say, it’s still subject to downgrade attacks at some points. Thanks for the correction.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: