Woo~
why you make me read analog clock, it wouldn't take 3 of my answers
Hope we get HTTPS and the old emotes back, the not having HTTPS in particular makes me feel a little unsafe.
I mean.. It probably would be a good idea to enforce https at least on the login page.
https is an important thing for a dynamic website like this. A lot of websites already use Let's Encrypt to do SSL certifications. Thing is though, I'm unsure how Tom is hosting the website, because some hosting providers do not allow Let's Encrypt. The old ShrineMaiden used Let's Encrypt, but that's because helvetica actually had full control over the virtual machine running on Linode and could do so. Some virtual private servers don't let you have full control like this, and the providers do not allow Let's Encrypt. It'll have to be seen.
https://letsencrypt.org/ <-- you get a SSL certificate here
https://certbot.eff.org <-- this makes sure that the certificate actually gets automatically renewed, so you wouldn't have to deal with the 3 month renewal thing that kept happening.
I'd say it's definitely a requirement because of LettyJournal, Passwords and Private messages. It's really easy for someone on the same network as you to snoop non encrypted connections. One more thing, I am connected to shrinemaiden.com via HTTPS, and it's using a self-signed cert. It has the same issue as before where the browser gives a big warning but it's certainly better than plain text.