Re: Making www.cpan.org TLS-only
[email protected] (Leon Timmermans) Tue, 5 Sep 2017 10:31:28 +0200
| Newsgroups | perl.cpan.workers |
|---|---|
| Message-ID | <CAHhgV8g4g0SEcNwxdZQ_W-n78xOofzG+VOO_yqV3w=sJZY_Ljw@mail.gmail.com> |
On Tue, Sep 5, 2017 at 6:34 AM, Ask Bjørn Hansen <[email protected]> wrote: > > Among things that should allow non-TLS: I would include /src/. Also the > top-level RECENT files, things in /indices/. > > +1. > > Maybe it makes more sense to reverse the logic and just targeting whatever > the most popular[1] web pages for browsers and count on HSTS having the > browsers sort it out; basically an expanded version of what we did now with > just the home page. That sounds like a more sensible approach to me. Leon