Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Maybe showing the "http-is-insecure" warning in the address bar only when the user fills form inputs?


This would be a great first step, maybe a new T0.5 in the transition plan. Get people on board by securing the data they are sending around, and the secure the pages they are reading later.


But what if the site loads JavaScript from an insecure origin?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: