The proxy would have to spoof the secure cookie flags (and also maybe rewrite JavaScript to request http instead of https) but MITM attacks are already costly, and bitbucket is a big, high value target; this is all within the reach of industrial espionage or state sponsored attack (or bored teens).
I just read up on hsts and hpkp. They both seem pretty broken in the face of http MITM attacks (why aren't they part of the secure dns stuff?!?). Also, hpkp is often disabled for self signed and imported (private) CA certs. sigh.
I just read up on hsts and hpkp. They both seem pretty broken in the face of http MITM attacks (why aren't they part of the secure dns stuff?!?). Also, hpkp is often disabled for self signed and imported (private) CA certs. sigh.
https://developer.mozilla.org/en-US/docs/Web/HTTP/Public_Key...
They both look much better than the django referrer hack though. Thanks for the pointer.