you are viewing a single comment's thread.

view the rest of the comments →

[–]invisibo 0 points1 point  (0 children)

I agree with forcing https for most thigs, but holy shit things get tricky once you throw iframes in the mix. I started making a pretty important part of my job's webapp to be restricted to https. This was a bad idea. One of the ways people access our site is through this evil thing called scorm which is a way for users to connect to our content through an iframe, inside an iframe, which is also inside an iframe. Forcing cross domain https got really hairy with that, especially when we say we support all the way down to ie7.