Comment on Other people's dataComments−richardwhiuk13yIrony: Proclaiming 'HTTPS everywhere' when the webpage it's on doesn't use HTTPS.−nc1713y"It goes without saying that all pages shown to logged-in users should be served over HTTPS"You're not logged on to that page, it's a blog. There's nothing to gain by serving it over https.−mentat13y"nothing to gain" has interesting intersections with domain-wide cookies when mistakes are made.−kodablah13y"But that isn't quite enough"..."HTTPS is easy to do and servers are plenty fast these days so there's really no excuse not to use it on all your pages, so that's exactly what we do!"Does seem a bit ironic.−andybak13yMaybe he thought "HTTPS Everywhere Except In Places That Obviously Don't Need It" didn't really roll of the tongue as well−belthasar13yOne line down ->It goes without saying that all pages shown to logged-in users should be served over HTTPS
Comments
Irony: Proclaiming 'HTTPS everywhere' when the webpage it's on doesn't use HTTPS.
"It goes without saying that all pages shown to logged-in users should be served over HTTPS"
You're not logged on to that page, it's a blog. There's nothing to gain by serving it over https.
"nothing to gain" has interesting intersections with domain-wide cookies when mistakes are made.
"But that isn't quite enough"..."HTTPS is easy to do and servers are plenty fast these days so there's really no excuse not to use it on all your pages, so that's exactly what we do!"
Does seem a bit ironic.
Maybe he thought "HTTPS Everywhere Except In Places That Obviously Don't Need It" didn't really roll of the tongue as well
One line down -
>It goes without saying that all pages shown to logged-in users should be served over HTTPS