A truly weird decision, perverse-outcome sounding, if you don't explain it. Maybe the burden of holding state for TLS turned out to be too much for their capital investment, and they decided that there was no transitive risk in being insecure HTTP protocol, for a public information service.
Or maybe something else?
An explanation might help. I am sure future 'scrape the web and report on HTTP/HTTPS' bots are going to flag this as insecure.
Comments
A truly weird decision, perverse-outcome sounding, if you don't explain it. Maybe the burden of holding state for TLS turned out to be too much for their capital investment, and they decided that there was no transitive risk in being insecure HTTP protocol, for a public information service.
Or maybe something else?
An explanation might help. I am sure future 'scrape the web and report on HTTP/HTTPS' bots are going to flag this as insecure.