Missing HTTPS on Logins
The cluster focuses on complaints about a website's login and signup pages transmitting credentials over unencrypted HTTP instead of HTTPS, raising security concerns like plaintext password exposure. Discussions also touch on authentication handling for sites requiring logins and suggestions like OAuth.
Activity Over Time
Top Contributors
Keywords
Sample Comments
can't believe they don't use https for their logins.
How come they aren't using HTTPS in their login form?
The site lacks ssl for the login.
Sorry to be the security weenie, but any chance we can get HTTPS for the login POST?
Why no SSL on the login / registration pages ?
Were people entering login details on non-encrypted dummy sites?
Will this work on sites that require a login to use?
afaik they do not actually handle your logins
Passwords don't protect against spoofed login pages.
Site asks for username and password on non-encrypted page.