Re: Making www.cpan.org TLS-only

[email protected] (Leon Timmermans) Tue, 5 Sep 2017 10:31:28 +0200
Newsgroups perl.cpan.workers
Message-ID <CAHhgV8g4g0SEcNwxdZQ_W-n78xOofzG+VOO_yqV3w=sJZY_Ljw@mail.gmail.com>
On Tue, Sep 5, 2017 at 6:34 AM, Ask Bjørn Hansen <[email protected]> wrote:

> > Among things that should allow non-TLS: I would include /src/.  Also the
> top-level RECENT files, things in /indices/.
>
> +1.
>
> Maybe it makes more sense to reverse the logic and just targeting whatever
> the most popular[1] web pages for browsers and count on HSTS having the
> browsers sort it out; basically an expanded version of what we did now with
> just the home page.


That sounds like a more sensible approach to me.

Leon