Re: [whatwg] Passwords

2014-10-18 Thread Anne van Kesteren
On Sat, Oct 18, 2014 at 7:14 PM, Roger Hågensen wrote: > This precludes that a site has a certificate, and depite someone like > StartSSL giving them out free, sites and forums still do not use HTTPS. We recently started doing this for whatwg.org. It was not a big deal (though quite a bit of work

Re: [whatwg] Passwords

2014-10-18 Thread Roger Hågensen
On 2014-10-17 17:09, Nils Dagsson Moskopp wrote: Roger Hågensen writes: Also http logins with plaintext transmission of passwords/passphrases need to go away, and is a pet peeve of mine, I detest Basic HTTP-Authentication which is plaintext. Note that Basic Auth + HTTPS provides reliable tran