Nobody denies SSL (or TLS) would be great

But it’s simply not possible for you to have a browser that makes it a pain (or makes it impossible) to login at sites which don’t have SSL for the login process. This blog has a login, and because there is no great security consequence to your blog password being stolen, I have not set it up for SSL, and neither have a zillion other blogs and sites.

Anything that says, “You can’t take passwords until you upgrade” or “You can’t login until you upgrade” had better be a truly wonderful solution, because it won’t happen otherwise.

Stage 1 solutions are those that allow either me as a site to protect my users and me from phishing, or me as a user to protect myself, with no change required elsewhere.

Reply

Please enter Brad's last name above. Case doesn't matter
Please make up a name if you do not wish to give your real one.
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.

More information about formatting options