Why Even Bother With Mixed Content?
This is the article I’m going to be writing about next.
I went to the HTTPS version of the site as it’s really a ‘best practice’ thing. The site is completely unusable. It’s the plaintext and nothing else.
Of course you can allow mixed content… but then you open a wide gaping hole that can allow an attacker to keylog or break your SSL in other ways.
It’s also just a pain in the ass to say “allow mixed content” every damn time.
blog comments powered by Disqus
Published
20 June 2012