You periodic reminder that HTTPS (excluding EV) is about protecting and trusting the connection, not the website.
3
61
40
@rgacogne @FiloSottile @directhex Not sure HSTS solves this entirely if the MITM is there from the start

May 14, 2015 ยท 7:31 PM UTC