Hacker News new | ask | show | jobs
by nc17 5004 days ago
"It goes without saying that all pages shown to logged-in users should be served over HTTPS"

You're not logged on to that page, it's a blog. There's nothing to gain by serving it over https.

2 comments

"nothing to gain" has interesting intersections with domain-wide cookies when mistakes are made.
"But that isn't quite enough"..."HTTPS is easy to do and servers are plenty fast these days so there's really no excuse not to use it on all your pages, so that's exactly what we do!"

Does seem a bit ironic.