Skip to content

Comment on Automatic HTTPS Enforcement for New Executive Branch .gov Domainsparent

Comments

It was a state jobs site which has since updated to HTTPS. They still suck in a lot of ways - the required login is SSN, plus an 8-digit (numeric only) PIN. That's a laughably bad login scheme, but at least they aren't passing it in the clear.

If I do see it again, is there anything like a clearinghouse for this sort of complaint?

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.