Earlier quoted context omitted.
The article said people were reporting that Gmail accounts have been hacked in an environment where malicious Wifi APs are prevalent. Your post said that report "sounds suspiciously false." My reply contended that it's possible. A device running something other than a recent version of a modern browser is entirely susceptible to connection to Gmail over a non-TLS pipe or TLS to a MITM, especially when that device is…
> Citing that the state of the art in browser technology exists does not change that point. > Do you agree it's possible the claim is true? HSTS preload lists are not new (the Mozilla blog I referenced above is dated 2012). > The article said people were reporting that Gmail accounts have been hacked in an environment where malicious Wifi APs are prevalent. Your post said that report "sounds suspiciously false." If i…
By the way, I wouldn't call these people technically illiterate. The way you're using that term sets a bar so high that it includes almost everyone. If many people were at that level of technical literacy, we wouldn't have needed HSTS in the first place.