|
|
|
|
|
by superkuh
530 days ago
|
|
This is part of why HTTP+HTTPS still has a place for non-commercial non-institutional just for fun/education websites. HTTP+HTTPS is also significantly less fragile than HTTPS-only over any years+ long timescales. Eventually even the tool keeping your CA TLS cert up to date itself will stop working or the root cert will expire, etc. HTTP+HTTPS means the site keeps being accessible. If the threat model allows it, it's better. |
|