Skip to content

Comment on Other people's data

Comments

Irony: Proclaiming 'HTTPS everywhere' when the webpage it's on doesn't use HTTPS.

"It goes without saying that all pages shown to logged-in users should be served over HTTPS"

You're not logged on to that page, it's a blog. There's nothing to gain by serving it over https.

"nothing to gain" has interesting intersections with domain-wide cookies when mistakes are made.

"But that isn't quite enough"..."HTTPS is easy to do and servers are plenty fast these days so there's really no excuse not to use it on all your pages, so that's exactly what we do!"

Does seem a bit ironic.

Maybe he thought "HTTPS Everywhere Except In Places That Obviously Don't Need It" didn't really roll of the tongue as well

One line down -

>It goes without saying that all pages shown to logged-in users should be served over HTTPS

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.