Page 1 of 1

HTTP where HTTPS is more appropriate (Individual Contributor's License Agreement)

Posted: Wed Dec 22, 2010 11:41 pm
by jasondivy
I'm not a contributor (yet), and haven't picked a project to focus on. Still, I like the idea of helping out.

I'm mildly concerned that the "Individual Contributor's License Agreement" submission page (including name, address, and phone) is submitted via unsecure HTTP.

I realize packet sniffing among Internet routers is rare. Still, I see no reason to avoid HTTPS in todays day and age for any personal data.

I agree...

Posted: Thu Dec 23, 2010 6:10 am
by allenjblodgett
I agree with you, I just don't can't change it myself... (try emailing Tom)

Posted: Thu Dec 23, 2010 2:28 pm
by mkmurray
jasondivy wrote:I'm not a contributor (yet), and haven't picked a project to focus on. Still, I like the idea of helping out.

I'm mildly concerned that the "Individual Contributor's License Agreement" submission page (including name, address, and phone) is submitted via unsecure HTTP.

I realize packet sniffing among Internet routers is rare. Still, I see no reason to avoid HTTPS in todays day and age for any personal data.
We're actually discussing this now as moderators. We're in the process of pointing out a few non-HTTPS sections of the site that should probably be switched to HTTPS. Thanks for your help.

Posted: Thu Dec 23, 2010 9:11 pm
by jasondivy
No, thank you. ;)