Probably depends on if their account gets hijacked at your site or the site of your fastest competitor.
I agree that anonymous or non-logged-in activity has no need of HTTPS, but anything that's transferring cookies, passwords, or other important user or session information should be HTTPS.
Comments
Probably depends on if their account gets hijacked at your site or the site of your fastest competitor.
I agree that anonymous or non-logged-in activity has no need of HTTPS, but anything that's transferring cookies, passwords, or other important user or session information should be HTTPS.