Hacker News new | ask | show | jobs
by kyboren 3410 days ago
CBC should not host that site on such a distinctive subdomain, as the hostname "securedrop.cbc.ca" will leak in the clear during the TLS negotiation. It would be far better to host the same content at, say, https://cbc.ca/securedrop.