• Doubletwist
    link
    25 months ago

    Once again you seem to be calling for not bothering with any security effort of there’s even a remote chance of some other vulnerability happening.

    The whole point of security is that it’s always a multi-layered thing. Nobody sane is pretending that encrypting web traffic with HTTPS is a panacea that’s going to solve all your data security needs. But it is sure as hell a million times better than having all of your data transmitted in the clear, with absolutely no assurance that you’re are talking to the system you think you’re talking to, or that the data hasn’t been tampered with in transit.

    And don’t pretend https is a huge burden. It’s dead simple to get SSL/TLS certs, and the additional load of encrypting and decrypting the traffic is barely even a rounding error on modern CPUs.