Skip to content

Comment on Ask HN: Sites using pop-up login windows without HTTPS? (e.g. Digg)

Comments

You're not technically required to use SSL for login forms, but it's a terrible idea not to. To say it's trivial to capture plain text login information might be the understatement of the millennium. It's basically a step up from not using any password at all. It can be tempting not to bother with an SSL certificate on a site that does not store personal information, but you're really doing a disservice to your users by not providing secure logins.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.