Reply to thread

Only if the user is stupid/not paying attention. SSLstrip works by proxying the HTTPS connection between the MITM and the server using an HTTP connection between MITM and the user. I'm not going to enter my credit card details or my bank account password if I see that the connection, which should be HTTPS, is not HTTPS.

 

In any case, this would be the user's fault. From a website owner's perspective, forcing everything over HTTPS and informing users about common-sense security is the best you can do.


Back
Top Bottom