This is untrue so please don't perpetuate this myth. If you send the `Cache-Control: public` header, the resource will be cached to disk just as it would without HTTPS.
That sentence is somewhat unnecessary as I wouldn't have posted that unless I believed it to be true. The rest of your post is valid enough (in fact extremely helpful) not to need to such a prefix.
Anyhow, I'm not out to start an argument and I genuinely am grateful you have corrected me because obviously I wasn't aware of the "public" option in the cache-control header and this is something I can actually put to use right away.
So thank you for the correction :)
You're right; sorry about that. I do get annoyed when I see bogus reasons for not deploying HTTPS. It's made all the worse by people who actually know better but spread FUD because they stand to make a profit from selling expensive HTTPS accelerator appliances. But that's clearly not the case here and doesn't excuse my comment, which, upon reflection, was too harsh.
[1] http://www.pcworld.com/article/262307/crime_attack_abuses_ss...
Sorry I didn't categorically spell this out for you earlier, I forgot some people need spoon-feeding the facts about the technology they advocate - even after you've already cited a massively dumbed down article on the subject already.
(and nasty tone of my post is a result of me getting fed up with the way how you, and everyone else it seems, feels is appropriate to talk to each other on HN. This place never used to be quite so rude)