Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Gmail credentials are supposed to be delivered over an encrypted connection. Controlling the network should be insufficient to see passwords in transit. That said, passwords are a poor form of authentication that is prone to interception by poorly configured clients, HTTP downgrade attacks, and typosquatting login forms. I wouldn't jump straight to "0day".


If you're using a browser without certificate pinning wouldn't a MITM attack suffice? E.g. sslstrip


gmail uses HSTS so sslstrip is unlikely.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: