Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Super informative, always seemed like http is fine unless you are doing something security critical. But even blogs use https.


> always seemed like http is fine

But it's really not, as countless comments here in this thread have correctly pointed out.


...because most people re-use the same password across all websites, despite decades of begging them not to. In which case, do you want a blog exposing their password in plaintext?

Nobody does; so there's very little to lose by also encrypting.


why would you need a password to view a blog


To leave a comment with a consistent identity


To log in and create a new blogpost?




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: