There's really no excuse for this nowadays. When someone browses the site, that should be between CFPB and that person, not NSA or any other snoops in between. Unless you have some requirement to support in-the-clear data transfer (and maybe even if so), HTTP URLs should be rewritten to HTTPS.
There's really no excuse for this nowadays. When someone browses the site, that should be between CFPB and that person, not NSA or any other snoops in between. Unless you have some requirement to support in-the-clear data transfer (and maybe even if so), HTTP URLs should be rewritten to HTTPS.