Abuse MITM possible regardless of HTTPS

XSS using quirky implementations of ACME http-01

Bypassing and exploiting Bucket Upload Policies and Signed URLs