Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yeah, this is an entirely valid criticism. It was more of a nitpicky point that they weren't flipping to HTTPS automatically, but from a practical standpoint it's no more secure if they did since they lack HSTS.

Struck it from the post.



but when you struck it out, the first impression is that it's actually not a problem, but in fact it's even a bigger problem. right?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: