Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Not sure why the author goes through pains not to call out the fact that SO is not secure in the layman sense. In general, if a service requires users to understand the lack of SSL and to take security into their own hands, the service is not secure. Worse than that, SO does not even explicitly communicate this to users.

Also, the author omits a crucial workaround. When on a public network, communication can be made secure if routed through an encrypted tunnel to a known-secure network, such as with a properly configured VPN.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: