@gelatin @wyatt Maybe I'm missing something. If an attacker on a coffee shop WLAN sniffs your session cookie for a forum, they can proceed to ruin your life by posting illegal material under your name. There used to be a browser extension called "Firesheep" that would snoop others' cookies for Facebook until Facebook went all HTTPS all the time.

#https #hsts #firesheep #facebook #PacketSniffer

@SwiftOnSecurity #Firesheep was a critical moment in the move to HTTPS everywhere for everything.
Killed the initial business speech for commercial VPN.
Nico's μBlog