TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

HTTPS is one of the least important things you can do to secure your site

4 点作者 daviddede超过 10 年前

1 comment

bradleyland超过 10 年前
How is this considered even remotely good advice? I agree that you should definitely do all of the other things advocated by the author, but why <i>not</i> use HTTPS everywhere? Because of the risk of engendering a false belief that your site is secure?<p>This is a rant based on a flawed principle; that if you can&#x27;t do it all, don&#x27;t do any of it. If you don&#x27;t use HTTPS, you will open yourself to <i>many</i> additional attack vectors. Why would any security professional give this advice? It makes no sense at all.