Skip to content

Comment on EFF: How to Deploy HTTPS Correctlyparent

Comments

Probably depends on if their account gets hijacked at your site or the site of your fastest competitor.

I agree that anonymous or non-logged-in activity has no need of HTTPS, but anything that's transferring cookies, passwords, or other important user or session information should be HTTPS.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.