Hacker News new | ask | show | jobs
by shmapf 3816 days ago
Is it me or is the page being served over an unencrypted channel a gaping security hole?

I presume it encrypts on the client side, but whats to stop a man in the middle swapping the javascript so it sends the attacker your files?

2 comments

Yes thank you, I should have taken care of this sooner.

It now force redirects, hats off to CloudFlare for being free SSL provider.

They should disable the http version.