Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

But what's insecure about the marketing pages being sent in the clear?

It's common practice to setup a subdomain for your secure communications so that you aren't having to send images, javascript and public pages through HTTPS. Load times are part of the reason, but the other is that it takes more resources on the server end too.

I'd love to hear your actual reasoning on this though.



Because the users go to the marketing page to find the login button. You're still just as vulnerable to MITM.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: