top | item 40459963

APIs Probably Shouldn't Redirect HTTP to HTTPS

9 points| ikisusi | 1 year ago |jviide.iki.fi

1 comment

order

ikisusi|1 year ago

I was suddenly much more afraid of widespread router takeover botnets with DNS MITMs re-emerging after stumbling on this. Started thinking about the cheer number of API traffic today combined with the realisation that some of it may be using plain text by mistake because of this redirect practice. :(