So I think the lack of 's' in http in the original link doesn't matter.
If I'm wrong, could you please explain why (I am reasoning as best I can, and am not an expert, and keen to learn).
So I think the lack of 's' in http in the original link doesn't matter.
If I'm wrong, could you please explain why (I am reasoning as best I can, and am not an expert, and keen to learn).
However, Heroku should also be smart enough to figure out that all links should be https and servers should have valid certificates.
For a company to make such basic security-related mistakes while in the middle of a bad security incident doesn't look good, to put it politely.
It sort of explains how they got where they are.
How hard is it for an attacker to do a MITM? Would the attacker need physical access to the user's wifi router?
or if you don't want to do it via BGP announcement you can just compromise any of the devices that are along the route between the client and the server. BGP is the rocket launcher of worldwide circuit compromise, but there's many other guns you can pick up
More colocation facilities in the US and Europe now do prefix filtering at egress - but this matters little, as there are still quite enough that don't. In contrast, there's virtually no prefix filtering in Africa or Asia (remember when an accidental BGP announcement from Pakistan killed YouTube worldwide?)
Obviously, you've checked the URL and seen that it's legit after, but realistically you should expect a legit email to not be feeding you a potentially insecure link.
Whether or not you're on top of your game, HTTP leaves you vulnerable to MITM attacks[0]. So this would leave the end user vulnerable to any of these attacks even assuming Heroku has everything else perfect.