Hacker News new | ask | show | jobs
by enraged_camel 3701 days ago
They are. Think about the fact that a lot of data exchange occurs via URL parameters (e.g. access tokens), so it would be a huge problem if they weren't also encrypted on HTTPS.