For today's #securityHygiene, I think I'll post about trust and HTTPS.
[web 101: HTTPS is the way your computer communicates securely with the server. (vs. HTTP)]
So we all know that we should only log-in or put in credit card info with sites over HTTPS, right?
Guess what: You have to make sure that every step of the way you've been HTTPS - an attacker could have put in a slight redirect to their site in one of the non-HTTPS pages otherwise.
(1/2)
@0x56 I love this about CoSo. You have a lotta fun shooting shit with peeps, and then the next moment you learn something!
@Fiikus_goddess - CoSoMagic :)
This is not an easy thing to do, especially when not all devs understand this and there is a misunderstanding that HTTPS is expensive and slow.
You should be able to find browser add-ins that help you maintain HTTPS, but it's still not a panacea.
If you do encounter a site that has this dark pattern, try to contact the owner and explain they really can't have your business until they fix this security hole.