Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That's not what's done. "No HTTPS" is equated with "non secure".


He also claims that Quantas "secured their site" by adding HTTPS to their login page, and that serving sites over HTTPS is "secure by default"


This is true. I can intercept your username/password during login by being in close proximity to you if you are logging into their website over plaintext HTTP. Not possible if it is protected by TLS (HTTPS).




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: