3 ms·
OK, I understand why creating specific handlers might warrant a heads up. I suppose I'm unsympathetic since every authenticated web app I've done in the last 1
by asg 16y ago
OK, I understand why creating specific handlers might warrant a heads up.
I suppose I'm unsympathetic since every authenticated web app I've done in the last 10 years has been SSL only. But that was too 'enterprisey' perhaps :). Also I imagine that this is such an obvious thing, it wasn't a case of being unaware of the issue, just taking a conscious risk-reward decision on being SSL-only. Particularly for the really smart developers at github. One could argue that since nothing bad (that we know of) happened before firesheep, it was a valid decision.
All in all, I think Firesheep has done a big favour to the web as a whole.
PS. this thread has degenerated to using github as an example, I should probably point out that I love and respect github. really.