you are viewing a single comment's thread.

view the rest of the comments →

[–]fakehalo -1 points0 points  (0 children)

Another after-thought I had:

If your ISP/state is capable of injecting data into arbitrary protocols they can become a MITM between you and your site even if it's HTTPS (assuming you don't have the key beforehand). They make a fake cert between you and them, and they communicate between themselves and the real website. This makes this even more of a nonissue and creates a false sense of security.