Google Services in HTPPS

By Víctor Sánchez Last update Nov 19, 2007 — Installed 1,617 times.

Archived Comments (locked)

in
Subscribe to Archived Comments 2 posts, 2 voices



Jesse Andrews Admin

The following is an archive of comments made before threaded discussions was implemented (November 16th, 2008)

 
Anmar Mansur Scriptwright

Victor, granted your script works in more cases than my Force HTTPS for GMail, GCal, and GDocs script, but yours only modifies the protocol to secure HTTPS after the page has loaded in non-secure HTTP and the damage was already done.

In a man in the middle attack scenario, the attacker will obtain access to an authenticated session with your Google service of choice, while you unknowingly continue to use the service over HTTPS feeling (falsely) secure.

I strongly suggest you modify your script or take it down immediately.

Cross
Presentational HTML allowed.
Use <code> for inline code and <pre> for code blocks. Use &lt; and &gt; for literal < and >.
We help break paragraphs and link your links.
or cancel