cfpb / regulations-site

(DEPRECATED) Web interface for viewing U.S. federal regulations and other regulatory information
Other
28 stars 43 forks source link

Site uses cleartext HTTP by default (no SSL) #667

Closed pmocek closed 7 years ago

pmocek commented 10 years ago

There's really no excuse for this nowadays. When someone browses the site, that should be between CFPB and that person, not NSA or any other snoops in between. Unless you have some requirement to support in-the-clear data transfer (and maybe even if so), HTTP URLs should be rewritten to HTTPS.

ascott1 commented 7 years ago

2.5 years later, I can officially close this issue 🔒 :sweat_smile: