Hacker News new | ask | show | jobs
by garrettr_ 3433 days ago
(SecureDrop developer here) That's why we created https://securedrop.org/directory (HTTPS, HSTS, preloaded, .onion available, etc.). Use that instead! Also, we have strong recommendations for the news organization's "landing pages" (e.g. https://theintercept.com/securedrop/), including requiring HTTPS, to prevent this and other obvious security issues.
1 comments

This a shameless plug?
At least he was upfront about it by putting a disclosure in parenthesis.