Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If it's using a self signed cert, it's as secure as HTTP, and should be treated a such.

That means your cookie shouldn't be sent. (And, optimally, the address bar becomes red.)

If you want to trust the self signed cert, you should be able to do so, and the optimal place for that is at an scary-looking icon on the same place the padlock would be.

Other features shouldn't depend only on the protocol used.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: