Hacker News new | ask | show | jobs
by thusoy 3656 days ago
Yes, self-signed certificates without a CA is MitM-prone, but that's the only thing Heroku enables. You're only given a username and password and have to do with whatever configuration they've done, thus the problems.