|
|
|
|
|
by troyhunt
4818 days ago
|
|
If there was something worth protecting on a personal blog site, it might be a different story. 1 is very on-topic - there's no way that data should be sent in the clear. HSTS is good, but unfortunately only partially supported. Agree on the secure cookie, but of course you need to drop the dependency on accessing it over HTTP before you do that. |
|
It's not about security here, it's about privacy.
https://willnorris.com/2012/12/all-https-all-the-time
> This blog isn’t terribly controversial. But if only the "controversial" stuff is private, then privacy is itself suspicious. Thus, privacy should be on by default.