← Back to context

Comment by block_dagger

6 months ago

But only you have access to your local network.

Good thing all networks everyone connects to are always known by that user to be secure

  • Do these APIs not require https?

    • The case here was just injecting a domain. There's another thread for this post pointing out you would also need to inject a malicious root cert for https traffic, which is correct, but not impossible (and given some bad/lazy practices I've seen places do when they sign their own certs for internal infrastructure, not a far stretch)

      2 replies →