Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Irony: Proclaiming 'HTTPS everywhere' when the webpage it's on doesn't use HTTPS.


"It goes without saying that all pages shown to logged-in users should be served over HTTPS"

You're not logged on to that page, it's a blog. There's nothing to gain by serving it over https.


"nothing to gain" has interesting intersections with domain-wide cookies when mistakes are made.


"But that isn't quite enough"..."HTTPS is easy to do and servers are plenty fast these days so there's really no excuse not to use it on all your pages, so that's exactly what we do!"

Does seem a bit ironic.


Maybe he thought "HTTPS Everywhere Except In Places That Obviously Don't Need It" didn't really roll of the tongue as well


One line down -

>It goes without saying that all pages shown to logged-in users should be served over HTTPS




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: