I'm surprised google can still make that mistake, making my account vulerable after going to so much trouble of protecting it with 2factor auth.
I'm surprised google can still make that mistake, making my account vulerable after going to so much trouble of protecting it with 2factor auth.
That is, perhaps Google require an HTTPS-only token for sensitive actions and the authentication token sent over HTTP is only used for basic personalization (like showing your username) and some unimportant actions?
Though I guess we know that someone who has stolen your HTTP authentication token could ask embarrassing baraza questions on your behalf ...
This practice of having a website respond to both http and https simply has to die. Google is not the only offender here, but I expected more from them, because they are very security sensitive.
Google, next time you accuse Chinese of hacking you, reconsider your practices.
The main reasons I encounter for not going HTTPS everywhere are:
1) Possible negative effect on search engine ranking during transition period.
2) 3rd party content from analytics tools and advert networks not supporting HTTPS.
3) Slower initial page load over mobile due to SSL handshake.
4) No-one else is doing it.
Hopefully these reasons will become less valid over time!