... if transmitted over plaintext http
... if transmitted over plaintext http
The only protection here is HSTS (which is not enabled by most websites, but major ones like banks will usually have them) and manually typing https:// in your address.
It might be worth it.
I remember spending hours trying to figure out why Google Adsense wouldn't render correctly. In the end I figured out that it was Adblock's fault :))
https://www.ssllabs.com/ssltest/analyze.html?d=commbank.com.... https://www.ssllabs.com/ssltest/analyze.html?d=nab.com.au&s=... https://www.ssllabs.com/ssltest/analyze.html?d=westpac.com.a...
CUA does have it - https://www.ssllabs.com/ssltest/analyze.html?d=ob.cua.com.au
Bankwest does but has some awful problems elsewhere - https://www.ssllabs.com/ssltest/analyze.html?d=ibs.bankwest....
But yeah, Westpac and NAB don't, and in addition to the ones you tested, ANZ and St. George don't have it either. That's pretty unacceptable really.
Is this issue any different to using open wifi at a cafe, which many many people do, relying on HTTPS for their security? (This is an honest question)
The risk is that you may do things on a protected network assuming it really is protected - this is more of a thing for organisations rather than consumers, for example organisations might have unprotected services accessible over their office wifi.