I'm not gonna be another growling at you about pico8 not being open source here aswell but at least fix HTTPS site wide.
No HTTPS on login and password changes is a huge security flaw and I'm stunned lexaloffle hasnt fixed this.
I can't imagine what other huge security holes are in pico8 waiting to be used to exploit pocketchip users.
captcha cat is cute tho. *ヽ(◕ヮ◕ヽ)
https://letsencrypt.org/ is what I'd recommend as well. Free, easy to use, and run by a nice company
https://security.googleblog.com/2016/09/moving-towards-more-secure-web.html?m=1
TLDR: SSL or your site with password input will be marked as insecure.
I'm really happy that Google is doing this.
[Please log in to post a comment]