Is it secure to submit from a HTTP form to HTTPS?

后端 未结 11 2096
悲哀的现实
悲哀的现实 2020-11-28 23:17

Is it acceptable to submit from an http form through https? It seems like it should be secure, but it allows for a man in the middle attack (here is a good discussion). Th

11条回答
  •  不知归路
    2020-11-28 23:31

    For me (as an end-user), the value of an HTTPS session is not only that the data is encrypted, but that I have verification that the page I'm typing my super-secrets into has come from the place I want it to.

    Having the form in a non-HTTPS session defeats that assurance.

    (I know - this is just another way of saying that the form is subject to an MITM attack).

提交回复
热议问题