Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Mailchimp thinks it's OK to have Mixed Content in 2020 (mailchimp.com)
3 points by Alupis on Sept 11, 2020 | hide | past | favorite | 1 comment


The Money Quote:

> This is because images in Mailchimp are stored in the cloud, not on the same server as the Mailchimp app. This doesn't affect the security of your Mailchimp data in any way. It just allows nonsecure items to display within our application.

No idea what any of that has to do with explicitly coding their system to fetch these resources over HTTP instead of HTTPS.

As a Mailchimp user, I can confirm this is indeed still how their system works. Mixed Content everywhere.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: