logoalt Hacker News

PunchyHamstertoday at 11:56 AM0 repliesview on HN

If you're worried about MITM in the TLS web connection between client and server, you already lost and no prevention method client side will work, because if you own the connection you can just give client malicious JS to extract the password when they enter it