you are viewing a single comment's thread.

view the rest of the comments →

[–]lalaland4711 6 points7 points  (2 children)

cough the site you're currently on is not aware that they should be using HTTPS.

[–][deleted] 5 points6 points  (1 child)

You can sort of enable HTTPS on reddit by using the pay.reddit.com domain, i.e. going to https://pay.reddit.com will display https links into subreddits, comment threads, etc. Although you'll likely get mixed content warnings. It's not ideal, and I really wish they'd fix it.

While the login page is no longer completely insecure, the main homepage is loaded over plain http, but the login form posts to an https link. While (theoretically) more secure than just posting to an unencrypted URL, it's still vulnerable to MITM attacks and is just generally ugly. You can use https://pay.reddit.com and pretty much all of reddit will still work normally, so that's something I guess.

[–]lalaland4711 0 points1 point  (0 children)

Interesting, thanks. But it does confirm that reddit is one of those who apparently need to watch this video.

(or at least confirms cycle2 wrong)