• Possibly linux
    link
    fedilink
    English
    arrow-up
    1
    ·
    2 hours ago

    That assumes that an adversary has control of the browser. The big reason you don’t want to send passwords over https is that some organizations have custom certs setup. It is better to just not send the password at all.